Fabric and Cloud Enterprise Design
1. Cloud Deployment Models
Cloud deployment models are defined by infrastructure ownership, access controls, and management.
| Deployment Model | Infrastructure Ownership & Usage Characteristics |
| Private Cloud | Dedicated exclusively to a single organization with no public access; hosted on-premises or outsourced. |
| Public Cloud | Owned and operated by a third-party provider; accessible to the general public, typically via subscription. |
| Hybrid Cloud | A combination of two or more cloud models (most commonly private and public clouds). |
| Community Cloud | Shared by multiple organizations with common requirements, such as a shared disaster recovery site. |
Design Factors: Selection depends on security needs, deployment complexity, and cost requirements.
2. Cloud Connectivity Options
Cloud connectivity defines how an enterprise network attaches to external cloud environments.
A. Cloud Direct Connect
-
Concept: A dedicated, private connection directly between an enterprise network and a public cloud provider (AWS, Azure, GCP).
-
Alternative To: Standard public internet connections or VPN tunnels.
-
Key Benefits:
-
Security: Uses a private connection path, avoiding public internet security risks.
-
Reliability: Provides granular control over uptime and SLA mechanisms rather than relying on unpredictable internet routing.
-
Speed: Delivers higher throughput and lower latency than internet-based transport.
-
B. MPLS Direct Connect
-
Concept: Uses an enterprise MPLS network to connect to a Direct Connect Partner (e.g., Megaport), which then bridges traffic directly to the cloud provider.
-
Use Case: Solves connectivity challenges when an organization is located outside a cloud provider's direct connection region.
C. Cloud OnRamp
-
Concept: A Cisco SD-WAN feature set that automates, simplifies, and secures site-to-cloud connections using a single, unified policy framework.
3. Cisco SD-WAN Cloud OnRamp
Cisco Cloud OnRamp extends SD-WAN fabric policies to public clouds, colocation facilities, and SaaS applications.
Key Benefits
-
Multicloud Automation: Extends SD-WAN fabric into public clouds and colocation facilities directly from branch sites.
-
Unified Security: Enforces consistent segmentation policies on-premises and via cloud-delivered SASE architectures.
-
Consumption Flexibility: On-demand orchestration of network resources across enterprise, provider, and colocation layers.
-
Optimal Application Experience: Delivers visibility into application performance metrics to dynamically improve user experience.
The 5 Core Use Cases
-
Cloud Interconnect: Automates SD-WAN connection orchestration to MPLS Direct Connect partners like Megaport or Equinix.
-
Cloud Hub: Enables site-to-cloud workload access and provisions site-to-site WAN connectivity over cloud provider backbones (e.g., Google Cloud).
-
Cloud OnRamp for Multicloud: Automates deployment of virtual SD-WAN routers (vEdge/cEdge) into transit virtual private clouds (VPCs) and transit gateways (AWS, Azure, GCP) via vManage, automatically forming secure IPsec tunnels.
-
Cloud OnRamp for SaaS: Uses real-time probing (measuring latency, packet loss, and jitter) to dynamically select the optimal path for SaaS application traffic.
-
Secure SD-WAN: Integrates with Cisco Umbrella to deliver cloud security features, including DNS-layer security, Secure Web Gateway (SWG), Cloud Firewall, CASB, and Cisco Talos threat intelligence.
4. Cisco SD-WAN Cloud Hub with Google Cloud
Integrates Cisco SD-WAN orchestration directly with Google Cloud infrastructure.
Deployment Options
-
Site-to-Google Cloud: Connects SD-WAN branches directly to Google Cloud workloads.
-
Site-to-Site: Uses Google Cloud's global infrastructure as a high-speed WAN transit backbone to interconnect enterprise sites.
DevOps & NetOps Integration
-
DevOps teams define custom application profiles in the Google Cloud Service Directory.
-
Cisco vManage automatically pulls this application metadata.
-
NetOps teams translate the metadata into automated SD-WAN traffic policies, optimizing performance based on live network telemetry.
Key Advantages
-
Ready-to-Go Network: Speeds up site provisioning using Google Cloud infrastructure automation.
-
Single Console Management: Provision and operate both Google Cloud resources and SD-WAN endpoints via vManage.
-
End-to-End Visibility: Complete operational telemetry across Google Cloud's global backbone.




