Cisco Catalyst SD-WAN for Government Overview
Security is a critical element of today's networking infrastructure. Network administrators and security officers are hard pressed to defend their network against attacks and breaches. As a result of hybrid clouds and remote employee connectivity, the security perimeter around networks is disappearing.
FedRAMP, the Federal Risk and Authorization Management Program, is a U.S.-government program that establishes a standardized approach for assessing, authorizing, and monitoring cloud service providers.
Cisco Catalyst SD-WAN for government incorporates encryption and security at its core:
-
Creates a restricted space called the federal boundary within the AWS GovCloud (U.S.).
-
Restricts access to federally cleared personnel.
-
Runs in Federal Information Processing Standard (FIPS) mode for all controllers.
-
Ensures that all data and control connections are Secure Hash Algorithm 2 (SHA-2) compliant.
-
Provides enhanced user session management.
-
Performs a real-time audit at the controller level.
-
Provides an automated Plan of Actions and Milestones (POA&M) report.
-
Enables customers to have their own dedicated Amazon Virtual Private Cloud (Amazon VPC) that automatically denies all HTTP requests unless specifically authorized.
-
Ensures protection by AWS services such as AWS Application Load Balancer (ALB), AWS Web Application Firewall (WAF), and AWS Shield. All the web services are behind the ALB and WAF for protection. They are also protected from distributed denial of service (DDoS) attacks by the AWS Shield.
-
Uses a role-based access without local users for Cisco Federal Operations, a Cisco team that maintains and monitors the environment.
Cisco Catalyst SD-WAN for government conducts annual penetration testing through Third-Party Assessment Organizations (3PAOs). In addition to testing, Tenable Security Center performs daily penetration scanning. Tenable Security Center is a component of the management Amazon VPC. For more information, see Cisco Catalyst SD-WAN components.
For more information on the general Cisco Catalyst SD-WAN security configuration, see the Security Configuration Guide, Cisco IOS XE Release 17.x.