Overview
Describes a sample network topology that integrates Direct Internet Access (DIA), Cisco Umbrella SASE auto tunnel, and DVTI to support secure remote and branch connectivity.
This topology consists of the following components:
-
WKST BR is the internal client or branch workstation
-
NGFWBR1 is the branch threat defense device
-
NGFW1 headquarters threat defense device
-
Cisco Umbrella
WKST BR is connected to NGFWBR1. The corporate network is reachable through NGFW1. The ingress interface of NGFWBR1 is named inside and the egress interfaces are named outside, outside2, and outside3 respectively.
A Umbrella auto tunnel is configured between NGFWBR1 and Cisco Umbrella.
All DNS and web traffic is sent through the Umbrella auto tunnel to Cisco Umbrella to be allowed or blocked based on the Umbrella DNS and web policy. This provides two layers of protection, one locally enforced by the Threat Defense device and the other cloud-delivered by Cisco Umbrella.
For the hub and spoke configuration, a VPN tunnel is configured between NGFWBR1 and NGFW1. An ECMP zone is configured on the primary and secondary static VTI interfaces on the branch node for link redundancy and loading balancing of VPN traffic.