SAN DIEGO — When enterprises move or expand to the cloud, they need to start thinking about the architecture of their WAN, and that quickly leads to analysis about the security of their WAN, said David Goeckeler, executive vice president of networking and security at Cisco, during a keynote at Cisco Live.

“We have to rethink how we deliver security in this cloud-first world,” he said, repeating a theme from his day one keynote at the event. Cisco is striving to deliver a powerful, simple, and secure experience to its entire portfolio of networking technology, including SD-WAN, Goeckeler explained.

“We know that when you’re considering your SD-WAN strategy, security is top of mind,” said Gee Rittenhouse, senior vice president of Cisco’s security business. “The last thing we want to do is force you to bolt on various security technologies” that add complexity and require more maintenance of an organization’s network, he added.

Cisco previously integrated its portfolio of security technologies to on-premise SD-WAN appliances and is now extending that approach to Umbrella, its cloud-based secure internet gateway. “Whether you choose to secure your SD-WAN with appliances or in the cloud, we’ve got you covered,” Rittenhouse said. Cisco also updated its security policy management tool to allow enterprises to set and manage policy across environments and devices.

“We have integrated everything we have into Umbrella,” backed by an intrusion prevention system using Talos for threat intelligence, Rittenhouse explained. “We’ve been on this journey for a while…Today we’re excited to announce for the first time we’re extending this capability to a full proxy and firewalling” to create a secure internet gateway.

SD-WAN Security Features

He describes it as “the fastest and easiest way of securing your SD-WAN,” and jumped into a demonstration on stage to show how it works with a branch office that just deployed SD-WAN. The tool automatically provisions for identity, intercepts domain name systems (DNS), and implements security policy. Cisco also demonstrated how the tool can detect malware infections on devices that are sending control traffic to the cloud.

Pointing SD-WAN tunnels to the same cloud is another feature that Cisco developed to help organizations create network tunnels from branch offices and automatically provision those tunnels to send traffic to the cloud. Once the traffic is in the cloud, firewall policies can be reviewed and IT managers can view traffic patterns and anomalies in real time, Rittenhouse explained.

The typical enterprise is using thousands of cloud applications, but some of those apps negatively impact the network, he said. Cisco’s technology can automatically flag those apps and others that are trying to evade security policies, identify risk scores, and allow IT professionals to edit application controls and set an ongoing policy to block them in accordance with their respective organization’s requirements. “You can trust us to secure your SD-WAN with a single click,” Rittenhouse said.

“We’re going to continue to drive innovation at every layer of the network,” and keep investing and thinking about how Cisco can resolve the difficult challenges the industry faces, Goeckeler said in his closing remarks.