Tech Field Day Extra at Cisco Live US 2025
Cisco N9300 Smart Switch and Hypershield Security for AI Scale
31m
Learn all about the new Cisco N9300 Smart Switch and its role in the data center. Cisco has launched Nexus Smart Switches designed for data center environments, featuring a 24-port, 100-gig switch currently shipping and a new 48-port, 25-gig top-of-rack switch becoming generally available in August. Both switches integrate 800 Gbps of services throughput, primarily offloaded to Data Processing Units (DPUs) that run Cisco HyperShield security. These Smart Switches aim to consolidate traditional networking and security devices into a single unit, with the Silicon One NPU handling network processing (routing, switching, VXLAN, multicast) and the DPUs providing dedicated firewall services. This architecture facilitates a complete isolation of management, with NetOps teams managing the network processor and SecOps teams directly controlling HyperShield software on the DPUs through separate dashboards for enhanced security and operational clarity.
The Nexus Smart Switches are designed to address key data center use cases including cloud edge, zone-based segmentation, and data center interconnect, with the top-of-rack use case being a major focus for future implementation. The switches provide a "before and after" consolidation view, illustrating how a single Smart Switch can replace multiple traditional switches and firewalls, streamlining infrastructure and reducing complexity. Provisioning involves activating DPUs with a simple command and establishing connectivity to the HyperShield public cloud controller. Traffic can be selectively redirected to DPUs for firewalling based on VRF or VLAN policies, ensuring that only necessary traffic is subject to deep packet inspection. The system also supports high availability with state synchronization between Smart Switches for Layer 2 and Layer 3 protocols, and integrates with Cisco Live Protect for rapid vulnerability remediation via EBPF policies.
HyperShield, initially conceived as a distributed advanced firewall, represents a forward-thinking approach to security by distributing enforcement points directly inside the kernel (via EBPF and the acquisition of Isovalent) and deeply within the network via the Smart Switches. It utilizes an intent-driven policy model, allowing security policies to be written once and enforced across both kernel-level agents and network guardrails. Key use cases for HyperShield include zone segmentation, autonomous application segmentation, and distributed exploit protection. By fingerprinting known good behaviors and detecting multi-step anomalies, HyperShield moves beyond traditional IDS/IPS signature matching to a more dynamic, graph-based anomaly detection. A "Digital Twin" capability allows for safe testing of firmware and policy updates, providing a confidence score before deployment. This innovative approach offers a consolidated, high-throughput Layer 4 security solution, complementing existing perimeter firewalls, and integrating with third-party firewall policies for comprehensive security management.
Presented by Javed Asghar, Director of Product Management, Data Center, Jacob Rapp, Senior Director, Product Management, Hypershield, and Maurizio Portalani, Distinguished Technical Marketing Engineer. Recorded live at Tech Field Day Extra at Cisco Live in San Diego, CA on June 10, 2025. Watch the entire presentation at https://techfieldday.com/appearance/cisco-presents-at-tech-field-day-extra-at-cisco-live-us-2025/ or visit https://techfieldday.com/event/clus25/ or https://Cisco.com for more information.
Up Next in Tech Field Day Extra at Cisco Live US 2025
-
Cisco Industrial IoT with Ruben Lobo
See the newest Industrial IoT Solutions from Cisco in this presentation. Cisco's Industrial IoT Business Unit focuses on providing consistent network architecture for connectivity outside traditional office spaces, covering rugged environments from manufacturing to mines. With two decades in the ...
-
Conquer Complexity - Cisco Unified Br...
Learn more about the latest routing and secure branch solutions from Cisco. Cisco is introducing a unified branch approach designed for deploying branches at scale with optimal reliability and security. This strategy emphasizes leveraging a cloud platform for consistent management, centralized in...
-
Beyond Visibility: The Age of Intelli...
Is your network reliable? Answer the question with Cisco Network Assurance. Cisco's vision for network assurance is to unify experiences across Catalyst, Meraki, and ThousandEyes platforms, building smarter, end-to-end capabilities. The goal is to provide a consistent troubleshooting experience f...