Call a Specialist Today! 800-886-5369


Isovalent Enterprise Platform

Universal Networking and Security for Kubernetes and Beyond

An eBPF-powered networking, security, and observability layer for Kubernetes, virtual machines, and physical servers — delivering cloud-native connectivity and runtime protection across any infrastructure.

eBPF-Powered Cloud-Native Infrastructure

Isovalent Enterprise Platform provides a unified networking and security layer built on eBPF, the Linux kernel technology that enables programmable, high-performance packet processing without kernel modifications. Purpose-built for Kubernetes environments but extending to VMs and bare-metal servers, the platform delivers connectivity, load balancing, runtime security, and deep observability from a single solution — replacing multiple point products with one consistent control plane across cloud, on-premises, and edge deployments.

Three Pillars of Cloud-Native Infrastructure

Reliable Connectivity

Universal networking that spans Kubernetes clusters, VMs, and physical servers across any cloud or on-premises environment. eBPF-based data plane processing delivers wire-speed performance with zero-trust micro-segmentation and end-to-end encryption built in.

Security & Compliance

Runtime security powered by Tetragon provides kernel-level visibility into process execution, file access, and network activity. Automated compliance auditing, real-time threat detection, and forensic-grade event recording meet the demands of regulated industries.

Rich Observability

Deep, context-aware visibility into application traffic flows, DNS queries, HTTP transactions, and Kubernetes service maps — without sidecars or application instrumentation. Identify latency bottlenecks, failed connections, and policy violations in real time.

Four Integrated Components, One Platform

Isovalent Enterprise Platform combines four tightly integrated capabilities that replace separate CNI plugins, service meshes, load balancers, and runtime security agents.

Networking for Kubernetes

High-performance CNI with native support for multi-cluster connectivity, IPv4/IPv6 dual-stack, BGP peering, and transparent encryption between nodes and clusters.

Runtime Security

Kernel-level enforcement powered by Tetragon for process execution control, file integrity monitoring, network policy enforcement, and automated forensic event capture.

Load Balancer

Scalable L3/L4 load balancing and ingress with XDP acceleration, DSR support, and Maglev-consistent hashing — replacing kube-proxy with dramatically lower latency.

Mesh Networking

Sidecar-free service mesh with mTLS, traffic management, and L7 observability. Extends connectivity beyond Kubernetes to VMs and external services without added complexity.

Enterprise Use Cases

High-Performance Kubernetes Networking

Replace legacy CNI plugins with an eBPF-native networking layer that eliminates iptables overhead, delivers wire-speed packet processing, and scales to thousands of services per cluster without performance degradation.

Cross-Infrastructure Multi-Cloud

Connect Kubernetes clusters, VMs, and bare-metal servers across AWS, Azure, GCP, and on-premises data centers with encrypted cluster mesh networking and consistent policy enforcement regardless of where workloads run.

Zero-Trust Micro-Segmentation

Enforce identity-aware network policies at the kernel level using Kubernetes labels, DNS names, and CIDR ranges. Prevent lateral movement between namespaces and clusters with policies that follow workloads as they scale and migrate.

Automated Compliance & Auditing

Capture forensic-grade records of every process execution, file access, and network connection at the kernel level. Automate compliance reporting for PCI DSS, SOC 2, HIPAA, and FedRAMP with continuous runtime evidence collection.

Real-Time Threat Protection

Detect and block container escapes, privilege escalations, cryptominers, and reverse shells in real time with Tetragon security policies that enforce at the kernel level — before malicious processes can execute.

Scalable Load Balancing & Ingress

Replace kube-proxy and external load balancers with XDP-accelerated L3/L4 load balancing that handles millions of connections per second with sub-millisecond latency and direct server return.

Open-Source Foundation

From the Creators of eBPF, Cilium, and Tetragon

Isovalent was founded by the creators of Cilium, the open-source eBPF-based networking and security project now maintained by the CNCF. Cilium is the default CNI for Google Kubernetes Engine, Amazon EKS Anywhere, and Azure AKS — trusted in production by organizations running some of the largest Kubernetes deployments in the world.

Tetragon, also created by Isovalent, brings eBPF-based runtime security observability and enforcement to the kernel level. Together, these projects form the foundation of the Isovalent Enterprise Platform, now part of Cisco’s cloud-native security portfolio.

Isovalent Enterprise Platform architecture built on eBPF, Cilium, and Tetragon

Cisco Security Ecosystem Integration

Isovalent Enterprise Platform integrates with the broader Cisco security portfolio to deliver end-to-end protection from the kernel to the cloud edge.

Integrations

Cisco Secure Firewall

Complement perimeter and east-west firewall enforcement with kernel-level micro-segmentation inside Kubernetes clusters for defense in depth across every network boundary.

Cisco Hypershield

Extend AI-native distributed security fabric with eBPF-powered enforcement points embedded directly in the Linux kernel of every node running containerized workloads.

Cisco Secure Workload

Combine application-level microsegmentation with kernel-level runtime security for comprehensive workload protection across Kubernetes and traditional server environments.

Kubernetes Distributions

Native support for GKE, EKS, AKS, OpenShift, Rancher, and Tanzu — with validated deployment guides and enterprise support for every major Kubernetes distribution.

Related Products

Cisco Hypershield
AI-Native Security

Cisco Hypershield

AI-native security fabric that embeds distributed enforcement points across your data center, cloud, and edge infrastructure for autonomous threat detection and response.

Cisco Secure Workload
Workload Protection

Cisco Secure Workload

Microsegmentation and workload protection platform that maps application dependencies and enforces zero-trust policies across bare-metal, VM, and container environments.

Cisco Multicloud Defense
Cloud Firewall

Cisco Multicloud Defense

SaaS-based cloud firewall protecting workloads across AWS, Azure, GCP, and Oracle Cloud with a single control plane for ingress, egress, and east-west traffic.

Get Started with Isovalent Enterprise Platform

Our Cisco-certified team can help you evaluate, license, and deploy Isovalent Enterprise Platform across your Kubernetes and hybrid infrastructure.

  • eBPF-native networking for any Kubernetes distribution
  • Runtime security and compliance automation with Tetragon
  • Multi-cluster and multi-cloud connectivity
  • Response from a certified specialist within one business day
Isovalent Enterprise Platform cloud-native networking and security