Skip to main content

Fabric and Cloud Enterprise Design

1. Cloud Deployment Models

Cloud deployment models are defined by infrastructure ownership, access controls, and management.

Deployment Model Infrastructure Ownership & Usage Characteristics
Private Cloud Dedicated exclusively to a single organization with no public access; hosted on-premises or outsourced.
Public Cloud Owned and operated by a third-party provider; accessible to the general public, typically via subscription.
Hybrid Cloud A combination of two or more cloud models (most commonly private and public clouds).
Community Cloud Shared by multiple organizations with common requirements, such as a shared disaster recovery site.

Design Factors: Selection depends on security needs, deployment complexity, and cost requirements.

2. Cloud Connectivity Options

image.png

Cloud connectivity defines how an enterprise network attaches to external cloud environments.

A. Cloud Direct Connect

image.png

  • Concept: A dedicated, private connection directly between an enterprise network and a public cloud provider (AWS, Azure, GCP).

  • Alternative To: Standard public internet connections or VPN tunnels.

  • Key Benefits:

    • Security: Uses a private connection path, avoiding public internet security risks.

    • Reliability: Provides granular control over uptime and SLA mechanisms rather than relying on unpredictable internet routing.

    • Speed: Delivers higher throughput and lower latency than internet-based transport.

B. MPLS Direct Connect

image.png

  • Concept: Uses an enterprise MPLS network to connect to a Direct Connect Partner (e.g., Megaport), which then bridges traffic directly to the cloud provider.

  • Use Case: Solves connectivity challenges when an organization is located outside a cloud provider's direct connection region.

C. Cloud OnRamp

image.png

  • Concept: A Cisco SD-WAN feature set that automates, simplifies, and secures site-to-cloud connections using a single, unified policy framework.

3. Cisco SD-WAN Cloud OnRamp

Cisco Cloud OnRamp extends SD-WAN fabric policies to public clouds, colocation facilities, and SaaS applications.

Key Benefits

  • Multicloud Automation: Extends SD-WAN fabric into public clouds and colocation facilities directly from branch sites.

  • Unified Security: Enforces consistent segmentation policies on-premises and via cloud-delivered SASE architectures.

  • Consumption Flexibility: On-demand orchestration of network resources across enterprise, provider, and colocation layers.

  • Optimal Application Experience: Delivers visibility into application performance metrics to dynamically improve user experience.

The 5 Core Use Cases

  1. Cloud Interconnect: Automates SD-WAN connection orchestration to MPLS Direct Connect partners like Megaport or Equinix.

  2. Cloud Hub: Enables site-to-cloud workload access and provisions site-to-site WAN connectivity over cloud provider backbones (e.g., Google Cloud).

  3. Cloud OnRamp for Multicloud: Automates deployment of virtual SD-WAN routers (vEdge/cEdge) into transit virtual private clouds (VPCs) and transit gateways (AWS, Azure, GCP) via vManage, automatically forming secure IPsec tunnels.

  4. Cloud OnRamp for SaaS: Uses real-time probing (measuring latency, packet loss, and jitter) to dynamically select the optimal path for SaaS application traffic.

  5. Secure SD-WAN: Integrates with Cisco Umbrella to deliver cloud security features, including DNS-layer security, Secure Web Gateway (SWG), Cloud Firewall, CASB, and Cisco Talos threat intelligence.

4. Cisco SD-WAN Cloud Hub with Google Cloud

image.png

Integrates Cisco SD-WAN orchestration directly with Google Cloud infrastructure.

Deployment Options

  • Site-to-Google Cloud: Connects SD-WAN branches directly to Google Cloud workloads.

  • Site-to-Site: Uses Google Cloud's global infrastructure as a high-speed WAN transit backbone to interconnect enterprise sites.

DevOps & NetOps Integration

  • DevOps teams define custom application profiles in the Google Cloud Service Directory.

  • Cisco vManage automatically pulls this application metadata.

  • NetOps teams translate the metadata into automated SD-WAN traffic policies, optimizing performance based on live network telemetry.

Key Advantages

  • Ready-to-Go Network: Speeds up site provisioning using Google Cloud infrastructure automation.

  • Single Console Management: Provision and operate both Google Cloud resources and SD-WAN endpoints via vManage.

  • End-to-End Visibility: Complete operational telemetry across Google Cloud's global backbone.