21.5 C
Canberra
Friday, March 20, 2026

Cisco secures AI infrastructure with NVIDIA BlueField DPUs


AI is reshaping how we course of knowledge, clear up advanced issues, and ship digital experiences. However your AI setting is simply as safe because the infrastructure it runs on—and attackers know precisely the place to search for weaknesses.

As you scale AI workloads nearer to finish customers, brokers, and machines, a important problem emerges: you need to maximize GPU and CPU utilization whereas additionally defending towards subtle, fast-moving threats.

Conventional safety fashions wrestle in these environments. Centralized firewall home equipment can turn into site visitors choke factors that don’t scale to AI-level throughput. Host-based software program brokers also can tax CPU sources you want for AI processing—and, in some instances, introduce operational danger in multi-tenant environments.

To handle this, Cisco and NVIDIA are partnering to redefine AI safety. By extending Cisco Hybrid Mesh Firewall to NVIDIA BlueField knowledge processing models (DPUs), Cisco brings stateful segmentation instantly into AI servers related to Cisco Nexus One AI front-end materials. The end result is a sturdy, hardware-accelerated, server-level safety structure that helps cease threats earlier than they attain your knowledge—maximizing safety with no efficiency tradeoff.

With Cisco Hybrid Mesh Firewall, you may outline coverage as soon as and implement it all over the place. This unified safety mannequin spans bodily and digital firewalls, cloud environments, and now the DPUs inside your AI servers.

Determine 1: Safety shut to each workload: NVIDIA BlueField DPUs and Hybrid Mesh Firewall

The front-end community: The true safety area

In AI infrastructure, crucial safety boundary is the front-end community, the place customers submit inference and coaching requests, storage methods trade datasets and checkpoints, and multi-tenant workloads typically share the identical servers. As a result of exterior site visitors enters right here, it’s the zone the place inspection and isolation matter most.

Entrance-end site visitors usually falls into two main flows:

  • Consumer → Compute (inference and coaching)
  • Compute ↔ Storage (knowledge ingest, dataset entry, checkpointing)

In AI environments, you may’t assume solely “some” site visitors wants inspection. Practically all of it does, and multi-tenancy calls for strict segmentation. That requires segmentation that may function at full line charge throughout the front-end material.

Conventional centralized firewall home equipment break this mannequin. Hair-pinning site visitors to an exterior firewall will increase latency and creates bandwidth bottlenecks, successfully a choke level for your entire cluster.

Bringing safety to the AI workload with DPUs

A greater mannequin is server-level enforcement utilizing DPUs. By working the firewall on an NVIDIA BlueField DPU—not the host CPU—you cut back the chance of tenant tampering and protect CPU/GPU cycles for AI workloads.

Cisco is redefining AI workload safety by imposing unified safety coverage utilizing Hybrid Mesh Firewall on AI servers with NVIDIA BlueField DPUs. This allows:

  • Air-gapped enforcement in multi-tenant and bare-metal environments
  • {Hardware}-accelerated 400G line-rate stateful segmentation in DPU
  • VPC-aware coverage enforcement on the community edge
  • Tremendous-grained observability per stream in {hardware} at scale
  • Lateral motion containment, serving to block east–west assaults on the server boundary
Determine 2: AI workload safety for front-end materials, NVIDIA BlueField DPUs with Cisco Hybrid Mesh Firewall

Cisco Nexus One simplifies how community coverage is constructed, deployed, and saved aligned with workload identification and context.

On every AI server, it discovers Kubernetes workload metadata and shares that context with Cisco Hybrid Mesh Firewall, which interprets it into application-aware, stateful segmentation guidelines:

  • Native discovery (Nexus One): A unified administration airplane runs on every AI server to gather Kubernetes stock metadata—workload/software identification, labels and annotations, namespaces, and so on.
  • Context-aware coverage (Hybrid Mesh Firewall): Makes use of the above metadata to generate application-aware, stateful segmentation insurance policies for every workload.
  • DPU enforcement: Insurance policies are enforced inline on the NVIDIA BlueField DPU with out exterior brokers or software program.
  • Kubernetes integrations: Optimized for the Isovalent Kubernetes suite (together with Cilium CNI and Hubble) and appropriate with commonplace Kubernetes environments.

“AI is remodeling each business, and the fast rise of AI factories is driving a rising want for cybersecurity at scale throughout enterprise infrastructure. By embedding Cisco’s Hybrid Mesh Firewall coverage into NVIDIA BlueField DPUs on AI servers, our joint prospects obtain high-performance, multi-tenant, intent-driven enforcement and hardware-accelerated safety, seamlessly related by way of Cisco Nexus One AI front-end materials.”

—Kevin Deierling, SVP of Networking, NVIDIA

Cisco Nexus One: Community coverage orchestration and visibility for AI front-end materials

Cisco Nexus One takes these capabilities additional by orchestrating advanced community insurance policies and sustaining end-to-end visibility with multisite implementations in AI front-end materials (as proven beneath). This simplifies operations, strengthens compliance enforcement, and offers a safety framework that scales as AI environments develop.

Determine 3: Cisco Nexus One; Nexus Hyperfabric AI front-end materials

Constructing the safe AI manufacturing facility of the long run

AI factories succeed when safety retains tempo with AI-scale throughput. By working Cisco Hybrid Mesh Firewall on NVIDIA BlueField DPUs, we offer distributed, in-server enforcement with 400G line-rate stateful inspection and fine-grained, flow-level observability—with out consuming CPU and GPU sources.

Paired with Cisco Nexus One for centralized community coverage and visibility, organizations can scale multi-tenant AI infrastructure with confidence, safe from the within out.

Safety is the primary service delivered on the DPU. Subsequent, we’ll develop by including extra AI-centric community companies working on DPUs.

Roadmap highlights

  • Managed Availability: Q3 CY26
  • Normal Availability: This autumn CY26

What’s new

  • Cisco Nexus One: Community coverage and visibility
  • Hybrid Mesh Firewall: Stateful segmentation on BlueField DPUs
  • Splunk: Safety observability integration

To strive the answer throughout Managed Availability in early Q3 CY26, please contact your Cisco account consultant.

 

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles