Multicloud Fabric Configuration Guide
Overview and purpose
Cisco Multicloud Fabric (MCF) is a Cisco operated, managed multicloud network fabric that provides a unified, secure overlay across sites and clouds. MCF enables seamless connectivity between on-premises sites (such as branches and campuses) and cloud networks, and inter-connectivity between different cloud providers (AWS, Azure, and GCP). Managed through the Cisco Cloud Controller, MCF provides a unified interface for managing applications and services across diverse platforms. The implementation is a two-step process: attaching networks to the fabric and defining the connectivity between them.
This article is about the configuration details for MCF's streamlined approach to multi-cloud networking, emphasizing automation, simplified integration, and unified management.
Supported Cloud Providers
- AWS, Azure, and Google Cloud Platform (GCP).
Target Audience
- Mid-market to large enterprises in sectors like retail, finance, healthcare, and manufacturing.
Key Operational Model
- Cisco manages the fabric (vPoPs); no networking VMs, controllers, or agents are deployed in the customer's cloud account.
Security Paradigm
- Zero-Trust Routing (deny-by-default) with stateless L4 security; supports service-chaining for L7 inspection via Cisco FTDv or third-party stacks.
Segmentation
- Identity-based; uses tags on networks (VPC/VNet) and sites to define connectivity instead of IP addresses or CIDRs.
Visibility
- Future Roadmap: Integrated ThousandEyes agents provide end-to-end visibility across sites, the fabric, and cloud environments.
Deployment Options
- Available via direct purchase, partner-led motions, and CSP marketplaces (allowing existing cloud commit usage).
Commercial Models
- Flexible choice between an uncommitted consumption model (pay-as-you-go) or a long-term commitment for volume discounts.
Geographic Coverage
- North America and Europe at launch (November 2026), with further expansion based on customer demand.
Licensing requirements
MCF is priced as a "Cloud-Like" pricing model - Scalable, consumption based offering.
1. Metered - Based on premium services, data transfer and customer attachments.
- Attachments (Site/ VPC attachments per region per cloud
- Data transfer (GB)
- Premium Services (GB) - Subnet Nat, FW, Service Chaining, Thousand Eyes
2. Licensing:
- Committed
- Uncommitted
Hardware requirements
There are no hardware requirements for the MCF solution since it's a Software as a solution. This section we can highlight the platforms that are supported and the cloud service providers and regions that are supported.
CSP and Regions Supported
- AWS - us-west-2; us-east-1; eu-west-1
- Azure - westus2; eastus; westeurope
- GCP - us-west2; us-east1; europe-west1
Supported MX-OS based Cisco Secure Router models
- C8455-MX
- C8355-MX
- C8235-MX
- C8121-MX
- Supported cellular variants
- Supported Wi-Fi variants
MX-OS based routers require
- Firmware 26.1.4 or later
- Network Feature Override to downgrade to SL0
Configuration steps
Access Cisco Multicloud Fabric Pages (Public Beta)
The navigation paths for Multicloud Fabric pages vary slightly, depending on whether you are a North American customer accessing Multicloud Fabric through Cisco Cloud Control or a European customer accessing Multicloud Fabric through the Meraki Dashboard. The available functionality is identical in both.
Cisco Cloud Control (North American customers)
- In the Cisco Cloud Control top navigation bar, select the Main menu icon.
- Under Apps, select Multicloud Fabric.
- From the left navigation, select Overview, Cloud Access, or Event Log to open the corresponding page.
Meraki Dashboard (European customers)
- From the left navigation, select WAN & Cloud.
- Select Overview, Cloud Access, or Event Log to open the corresponding page.



- Users attach cloud and site networks to the fabric through a point-and-click interface.
- MCF automates integration and provisioning of cloud networks, eliminating manual configuration tasks.
- The zero trust routing model minimizes routing requirements by defining intent rather than opening broad connections.
- MCF provides unified visibility and management for all onboarded networks and connections across different environments.
The document is divided into the following configuration and monitoring sections:
- Simplified Fabric Attachment and Network Integration
- Automated Provisioning and Configuration Efficiency
- Implementing Zero-Trust Intent-Based Routing
- Unified Management and Cross-Environment Visibility
Simplified Fabric Attachment and Network Integration
This section explains the integration of Public Cloud Accounts with Cisco MCF.

Before networks can be attached to the fabric, MCF must be granted permission to discover the resources within your cloud accounts. This process varies slightly depending on the cloud provider.
AWS integration

- Permissions: MCF requires specific access rights to view VPCs.
- Configuration: You must create a permission policy and an IAM role with a trust policy within your AWS account.
- Validation: Once the IAM role is created, provide the Amazon Resource Name (ARN) to MCF. The system validates the role and automatically discovers all VPCs associated with that account.
Azure integration

- Requirement: Integration is managed through a Service Principal.
- Scope: This allows MCF to integrate and discover VNETs across one or multiple Azure subscriptions.
Google Cloud (GCP) integration


- Requirement: Integration requires a Service Account.
- Scope: This enables MCF to access and discover VPCs across one or more GCP projects.
- Once these integrations are complete, all discovered VPCs and VNETs will appear on the MCF Overview page.
Automated Provisioning and Configuration Efficiency
Onboard Cloud Resources or Cloud Attachment

Prerequisites
Before beginning the onboarding process, ensure that your cloud accounts (AWS, Azure, and GCP) are successfully integrated and that MCF has completed the initial discovery of your VPCs and VNETs.
Initiate the Onboarding Workflow
- Navigate to the Cisco Cloud Controller dashboard.
- Select the Multi-Cloud Fabric (MCF) service.
- Click on Onboard Network and select VPCs/VNETs.
Validate Cloud Integrations
- The initial screen displays all cloud environments currently integrated with MCF.
- Confirm that the correct AWS Accounts, Azure Subscriptions, and GCP Projects are listed.
- This step ensures you are targeting the specific environments where your intended networks reside before proceeding to isolation.
Select Networks for Onboarding
- View the list of discovered cloud networks. By default, the system filters for non-default networks, though you can toggle the view to include default VPCs/VNETs.
- Select the networks you wish to bring into the fabric. You can select a single network, a specific subset across different providers, or all discovered networks at once.
- Click Next to move to the Review and Configuration screen.
Configuration and Execution
- Review Selection: Confirm the summary of VPCs and VNETs to be onboarded.
- Advanced Capabilities (Optional): As the platform evolves, additional features like overlapping IP support (NAT) can be configured here to avoid the operational burden of re-addressing existing networks.
- Execute: Click Execute to begin the provisioning process.
Automated Orchestration (Behind the Scenes)
- Once execution begins, MCF automates the complex networking tasks that typically require manual intervention. The system performs the following:
- Provisioning Handoff Objects: Automatically creates AWS Virtual Private Gateways (VGW), Azure VPN Gateways, or GCP VPN Gateways for each selected network.
- Tunnel Establishment: Builds secure VPN tunnels between the cloud networks and the Cisco-operated MCF vPOPs (virtual Points of Presence) in the corresponding regions.
- Routing Automation: Automatically configures BGP and stitches together the routing across different clouds, removing the need for manual route table management.
Monitor Progress and Verification
- Onboarding is a real-time provisioning step and varies by provider:
- AWS and GCP: Typically complete in 10 to 15 minutes.
- Azure (VNETs): May take between 30 to 40 minutes due to Azure gateway propagation times.
- You can monitor the status on the MCF Overview page.


Success: The network status will update to Successfully Onboarded.
Failure: If a process fails, the network will show an Offline status. A notification banner will appear at the top of the interface providing specific error details for troubleshooting and remediation.
Onboard Meraki Sites or Site Attachment

Overview
Once cloud networks are integrated, the next phase is to attach physical site networks. Multi-Cloud Fabric (MCF) utilizes deep integration with Meraki Auto VPN to streamline this process. Unlike cloud network onboarding, a separate discovery workflow is not required, as MCF automatically discovers all networks within the associated Meraki organization.
Access Meraki Site Onboarding
- Open the Cisco Cloud Controller and navigate to the Multi-Cloud Fabric (MCF) dashboard.
- Select Onboard Network from the menu and choose Meraki Networks.
Select Site Networks (Hubs and Spokes)
The interface will display a complete list of all Meraki networks (Hubs and Spokes) identified in your organization.
- Hub Networks: These are pre-selected by the system and must be included in the initial Meraki site onboarding run to establish the core site-to-fabric architecture.
- Spoke Networks: These represent your branch or site networks. You can granularly select which specific spokes you wish to attach to the fabric at this time.
Configure Regional Connectivity
- In this step, you define the relationship between your physical sites and the MCF regions.
- An MCF region only becomes "Active" once at least one cloud network (AWS, Azure, or GCP) has been onboarded in that specific region.
- Hub Onboarding: MCF automatically onboards all selected Hubs to all currently active MCF regions.
- Spoke Onboarding: You must selectively choose which regions each spoke will connect to. This replaces manual regional vPOP design and route propagation.
- Proximity Strategy: Onboard a spoke to the closest geographic region to minimize latency, then utilize the MCF backbone to reach remote workloads.
- Direct Strategy: Onboard a spoke specifically to the regions where your primary workloads are running.
- Refine Selection: You can customize settings per spoke (e.g., removing a specific AWS or Azure region for one branch while keeping it for others).
Review and Execute
- Advance to the Summary screen to review the entire onboarding scope, including the selected sites and their target regions.
- Click Execute.
Automated Integration and Convergence
- MCF handles the Meraki Auto VPN orchestration behind the scenes. This process is significantly faster than cloud provisioning:
- Orchestration: MCF joins the Auto VPN domain and establishes the necessary connectivity parameters automatically.
- Duration: The integration typically completes in under one minute.
- Health Verification: After the initial setup, the system will take a brief moment to verify Auto VPN connectivity and converge to a Healthy status.

Completion of this workflow signifies that both cloud environments and physical site networks are successfully attached to the Multi-Cloud Fabric. You are now ready to proceed to Step 2 of the overall process: defining specific connectivity policies between these onboarded networks.
Implementing Zero-Trust Intent-Based Routing

Zero-Trust Routing is Cisco Multicloud Fabric’s architectural paradigm: nothing connects by default. Attaching a VPC, VNet, or site to the fabric does not let it talk to anything. A connection (port/protocol intent against a named application) must be explicitly defined. This collapses connectivity and baseline
security into one operational act, enforces deny-by-default at the fabric, and keeps route tables minimal. ZTR is stateless.
Unlike traditional network designs that rely on open communication pipes restricted by layered ACLs or firewall rules, the Multi-Cloud Fabric (MCF) utilizes a Zero Trust Routing paradigm. In this model, networks attached to the fabric cannot communicate by default. Policy is not tied to static IP addresses; instead, connectivity is established based on explicit intent. MCF selectively programs only the minimum routing required to fulfill that intent, significantly reducing operational overhead and avoiding route limitation issues as the environment scales.
Initiate Resource Connection
- Navigate to the MCF Overview page within the Cisco Cloud Controller.
- Click on the Connect Resources button.
Define Connection Identity
- Name: Provide a clear, helpful name for the connection (e.g., "Branch-to-Inventory-App").
- Description: Enter a detailed description for administrative tracking and auditing purposes.
Select Connection Endpoints
- Multi-Cloud Fabric allows for flexible connection types, including Site-to-VPC, VPC-to-VNET, or Cloud-to-Cloud.
- User can select multiple networks on either side of the connection.
- Left Side (Source): Select your primary resources.
- Example: Select specific site networks (e.g., VA and E sites) and a GCP VPC (e.g., Data Lake).
- Right Side (Destination): Select the target resources.
- Example: Select the AWS Inventory VPC where your target application resides.
Review and Submission
- Advance to the Review Connection screen.
- Verify that all selected sites, VPCs, and VNETs are correctly mapped.
- Click Submit.
Automated Route Propagation
- Once submitted, MCF handles all background orchestration to realize the defined intent:
- Selective Advertisement: MCF selectively advertises only the necessary routes required for the specific connection, maintaining a lean routing table.
- Route Programming: The system automatically handles route propagation across the multi-cloud environment, eliminating manual configuration of individual gateways.
- Convergence Time: Routing typically converges in under 2 minutes, at which point traffic will begin to flow according to the explicit intent defined.
Conclusion: This two-step process—Attaching (onboarding) and Connecting (defining intent)—replaces manual routing, BGP configuration, and complex security rule management with a unified, intent-based workflow.

