Alkira > Resources > Integrated Security and Network Services > Simplified Security with Alkira and Cisco Secure Firewall Threat Defense Virtual

Simplified Security with Alkira and Cisco Secure Firewall Threat Defense Virtual

Simplified Security with Alkira and Cisco Secure Firewall Threat Defense Virtual

The Cisco Secure Firewall Threat Defense Virtual (formerly FTDv) integration from Alkira’s Marketplace provides seamless security service insertion for any network connected to the Alkira Cloud Exchange Points (CXPs). Alkira allows customers to avoid the complexity to deploy and maintain their own Cisco Secure Firewall instances in the native cloud environments. This enables our customers to gain full visibility and control of:

  • Traffic from customer on-premises networks to the cloud
  • Traffic between virtual networks in the same cloud provider
  • Multi-cloud traffic between different cloud providers

Figure 1: Cisco Secure Firewall Threat Defense Virtual + Alkira Solution OverviewWith this integration, customers can leverage Cisco Secure Firewall Threat Defense Virtual in the Alkira CXP as a service and extend their enterprise security postures to the cloud. Customers can simply assign cloud networks to groups, and then configure and apply Alkira’s Intent-Based Policies to traffic flows between the groups and intelligently steer them to the Cisco Secure Firewall Threat Defense Virtual services.

Cisco Secure Firewall Threat Defense Virtual can be used for:

  • Next-Generation Intrusion Prevention System (IPS)
  • Stateful Firewall Inspection
  • URL Filtering
  • Application Visibility and Control
  • Malware Defense

Figure 2: On-Premise Firewall Management Center (FMC) and Cisco Secure Firewall in Alkira CXPCustomers can deploy multiple instances of Cisco Secure Firewall in regional Alkira Cloud Exchange Points (CXP’s) to provide security policy enforcement for application traffic between any set of endpoints connected to the Alkira global cloud backbone.Figure 3: Firewall Management Center Virtual (FMCv) on Public Network and Cisco Secure Firewall in Alkira CXP

Typically in customer environments, Cisco Secure Firewall instances are managed by the customer’s existing Firewall management Center. This platform can either be delivered as an on-premises appliance, or a virtualized appliance running in the cloud (Cisco Secure Firewall Management Center Virtual, FMCv).

Deployment of Cisco Secure Firewall Threat Defense Service

Figure 4: Firewall Deployment Steps in CSP and Alkira CXPImplementing an enterprise grade security architecture using any firewall NVAs is complex and involves several steps. However, Alkira simplifies the deployment of Cisco Secure Firewall instances in your Alkira tenant with only three steps.Figure 5: Alkira UI PortalYou access your managed cloud infrastructure of Alkira Tenant using a unique URL permitted to be accessed via only allowed-list of your IP addresses.Figure 6: Alkira CXPThe Cisco Secure Firewall Service can be deployed in any regional Alkira Cloud Exchange Point (CXP) through the Alkira’s Service MarketPlace. In the left panel of the CXP, you can choose to connect your on-premises, remote offices/branches, partners, and remote users using different connectivity options as Direct Connect/Azure Express, SD-WAN, IPSec and Alkira’s VPN Client. From the right panel of the CXP, you can connect your cloud resources (AWS, Azure, GCP, OCI) and also provide Internet connectivity to any resources connected to your Alkira tenant.Figure 7: Single Page UI configuration for Cisco Secure Firewall Service in CXPNow let us look at the three steps for deploying a Cisco Secure Firewall Service in Alkira. So in the first step, from the Services panel of the CXP, you will configure the Cisco Secure Firewall Threat Defense Service with a single UI configuration page. While configuring the service, you can choose to allow Auto-Scale of the instances as per your business requirements, this is the second step.Figure 8: Defining traffic selection policy in Alkira for Cisco Secure Firewall Threat Defense ServiceBy default, there is no traffic sent to the firewalls in the CXP. In the third and final step, you configure the Alkira Policy to select which traffic must go through the firewall before reaching the destination. Once all three steps have been completed, you have finished your deployment of the Cisco Secure Firewall Threat Defense Service in Alkira.

With Cisco Secure Firewall in Alkira, customers can inspect traffic flows from cloud to cloud (intra and inter/multi-cloud), cloud to on-premises, on-premises to cloud, on-premises/cloud to Internet, and more. In addition, Cisco Secure Firewall allows customers to implement use cases for URL filtering, application visibility and control, as well as malware defense.

Furthermore, Alkira and Cisco’s partnership simplifies the deployment of enterprise grade security in the cloud while enabling multi-cloud visibility and end-to-end threat defense for customers.

About Alkira

Alkira is the leader in cloud networking as a service. We unify multiple clouds, sites, and users via an enterprise network built entirely in the cloud. The network is managed using the same controls, policies, and security network admins know, can instantly scale as needed, and is available as a service. There is no new hardware to deploy, no software to download, and no cloud architecture to learn. Alkira’s solution is trusted by Fortune 100 enterprises, leading system integrators, and global managed service providers. Learn more at alkira.com and follow us @alkiranet.

To learn more about how Alkira can help simplify cloud networking for your organization, reach out and schedule a demo today.

Take our 30 minutes challenge and see how you can secure your network for the cloud era.

You May Also Like

Alkira mobile app screens

Introducing the Alkira Mobile App: Network Visibility Wherever, Whenever

Enterprise networks are expected to run 24/7, and the teams responsible for them need visibility wherever work happens. Cloud environments, partner connections, security services, and provisioning workflows are constantly changing. When something needs attention, network and operations teams need a fast way to understand what happened, assess impact, and take the right next step. That...
Jacob Donovan
Simple diagram showing a network as a platform

The Network Needs To Be Part of Your AI Strategy

Enterprises are moving quickly on AI, but many are still running networking models designed for a slower, more centralized and static era. Today’s network has to connect clouds, data centers, campuses, branches, partner environments, and increasingly private AI infrastructure while enforcing consistent policy across all of it. That creates a new operational reality: every new...
Calvin Nguyen
Blue network shield checkmark illustration

Navigating DORA: Operational Resilience and Security by Design

The Digital Operational Resilience Act (DORA) is reshaping how financial institutions in the European Union manage operational risk related to information and communication technology (ICT). As the regulation takes effect, organizations must ensure that their critical ICT service providers support strong operational resilience, risk management, and oversight capabilities. For technology providers supporting financial institutions, this...
Misbah Rehman