It’s been nearly 15 years since I attended my first Cisco Live, and last week in San Diego might have been the most memorable yet. Not just because of the scale of the event or the 23 Isonauts who flew in, but because of what we announced: the Isovalent Load Balancer, the Isovalent Network Bridge, and Live Protect, Cisco’s new runtime security capability powered by Tetragon and eBPF. But before we get into that, a quick rewind. This was my sixth Cisco Live, but each one has felt completely different. The first was in London, back in 2011, before I had even joined Cisco. Then came Milan in 2014, my debut as a Cisco employee. A year later I was back in Lombardy, for my first time presenting. Then came a long break, nearly a decade away from Cisco Live, until I returned following Cisco’s acquisition of Isovalent. At last year’s event in the sweltering Las Vegas heat, our presence was limited. The acquisition had only just closed, and we were still finding our feet. By the time Cisco Live Amsterdam arrived earlier this year, we were ready to introduce ourselves properly to the Cisco networking community. Fast forward four months, and we arrived in San Diego, just in time for the June Gloom. This time, Isovalent’s presence was impossible to miss. Let's recap our major announcements and moments of Cisco Live. Introducing the Isovalent Load Balancer Over 12 years after Cisco exited the load balancing market, it has returned with the Isovalent Load Balancer. Built on eBPF, the Linux networking fast-path XDP, and the lightweight Envoy proxy, this new load balancer is so fast and performance tests so impressive that some users initially thought their monitoring tools were buggy. You can learn more about it in the ILB launch blog post, try it out in the Load Balancer online lab, or sign up to hear Thomas and Liz explain the architecture and use cases in more detail. The ILB wasn't our only major networking announcement of the week. Introducing the Isovalent Network Bridge Over the past 18 months, we’ve seen exponential growth in demand from users looking to manage both containerized and virtualized workloads under a single control plane. At the same time, more and more teams are exploring how to migrate virtual machines across platforms - whether from legacy infrastructure or between modern environments. These trends are driving the need for infrastructure that connects diverse compute platforms such as Kubernetes, KubeVirt, Nutanix, OpenStack, and others into a cohesive operational model. While many of these platforms offer unified management for newly deployed workloads, they rarely provide a clean, low-risk path for migrating existing virtual machines without disruption. That’s where the Isovalent Network Bridge comes in. The Isovalent Network Bridge enables the migration of virtual machines while preserving their network identity at both Layer 2 and Layer 3, ensuring continuity and minimal disruption. In the demo below, you’ll see: Virtual machines being bulk-migrated from a traditional virtualization platform to Kubernetes, with their IP addresses preserved Live traffic from those VMs visualised through the Isovalent Hubble UI Cilium Network Policies enforced on Kubernetes-managed VMs, just as they would be on native containers The result is a unified, policy-driven environment that simplifies the transition to Kubernetes without sacrificing visibility or control. The Isovalent Network Bridge is currently in development and in limited access, with wider access planned for later this year. If you'd like to learn more, reach out to your Cisco account team or contact the Isovalent team directly. To support the Cisco community in navigating the evolving world of containerisation and virtualisation, my teammate Dan Finneran (who also contributed to this blog) delivered a Cisco University session in San Diego during Cisco Live titled “Modernising Virtualisation with Kubernetes, KubeVirt and Cilium.” In this talk, he explored how these technologies come together to form a modern, unified stack - and how enterprise vendors are beginning to adopt it. You can try it yourself, with our KubeVirt and Cilium online lab: Introducing Cisco Live Protect Patching network infrastructure is a slow, painful process - and I say that from experience. When a critical CVE drops, you're often left racing against the clock, knowing the patch may be weeks away. And when the fixed software is finally available, you still have to coordinate upgrades across fleets of devices. It might have been a while since I worked in network operations but I remember the pain. That’s why the introduction of Live Protect received such a fantastic reception. Built on Isovalent Runtime Security and the power of Tetragon and eBPF, Live Protect can automatically apply shielding for known vulnerabilities on Cisco networking gear. It delivers compensating controls within minutes of a CVE being disclosed, significantly narrowing the window of exposure. Live Protect was announced by Jeetu Patel, Cisco’s President and Chief Product Officer, during the Cisco Live keynote. It will first be available for NX-OS in September 2025, with broader platform support to follow. We will be publishing more details in the coming days - meanwhile, you can watch Jeetu's announcement below: The following demo gives you a taster of what's to come with Live Protect: mitigating CVEs on your Nexus estate while visualizing the results on Splunk dashboards! Introducing the Hubble Network Security Assessment We’re also excited to share a first look at a new capability designed to help teams strengthen their Kubernetes security posture: the Hubble Network Security Assessment. Network policies are one of the most effective ways to reduce attack surface in Kubernetes clusters. Cilium Network Policies provide fine-grained rules at Layers 3, 4 and 7, with protocol support such as DNS, HTTP, Kafka, gRPC. However, introducing them can be complex, particularly for teams that aren’t familiar with Kubernetes network policy models (we even wrote a "Network Policies Done The Right Way" book to help platform and network engineers with this subject). The first step toward improving posture is understanding where you stand. Hubble Network Security Assessment introduces a visual tool that scans a cluster and provides an actionable security posture report based on best practices for segmentation and exposure control. What this delivers today: A network security posture score, summarizing the current exposure level of your cluster A visual report organized by severity (critical, high, medium, low) with clear guidance on next steps Automated assessment across three levels of segmentation: Cluster segmentation: evaluates North-South ingress and egress exposure Namespace segmentation: checks East-West traffic across namespaces and verifies the presence of default deny rules Workload segmentation: highlights workloads not covered by any policy In this initial release, the scoring and ruleset reflect Isovalent’s recommended best practices. Future versions will allow security teams - CISOs, Security Architects, and others - to define and customize posture goals in plain language. Because the assessment supports multiple clusters, organizations will be able to enforce consistent security standards across their entire Kubernetes footprint. What is on the roadmap: Historical tracking of posture improvements and regressions Expanded rulesets based on observed traffic Linting and policy optimization suggestions Auto-generated policies to improve posture based on live flows This feature is designed with multiple personas in mind: from CISOs and Security Architects who define strategic posture, to platform teams and developers who are responsible for implementing it. The Hubble Network Security Assessment is currently in preview and we welcome feedback as we continue to develop it. It’s an important step toward simplifying the journey to Zero Trust in Kubernetes environments. To enquire about the preview, contact us for a personalized demo. eBPF everywhere eBPF-based technologies were ever-present at Cisco Live. We’re used to this at KubeCon (I remarked in our KubeCon North America 2023 recap how our relatively-small company presented over 20 sessions) but it was the first time that Cilium, Tetragon and Isovalent were taking over Cisco Live. I suspect it won’t be the last. A search for Hypershield, eBPF, Isovalent, Tetragon, Cilium on the Cisco Live session catalog listed 44 sessions. Admittedly, that’s only 2.5% of the 1,751 sessions (!!) at Cisco Live but that’s a pretty good start. Let's put the spotlight on some of my favourite sessions (CCO login required): Architecting Private Cloud Networking & Services with Cisco Nexus and Cilium Enterprise - by Christopher Luciano and Stephen McCabe Security superpowers with eBPF and Tetragon - by Liz Rice Enhancing Cloud-Native Security: Isovalent's CNI Innovations in Kubernetes - by Dirk Stoeckmann The Swiss Army Knife of Cloud Native Networking - by Raymond De Jong From Zero to Multi-Cloud Hero in 60 Minutes - by Matthew Howlin and Pedro Antúnez Network Engineering in the era of Microservices - by Jorge Gomez Velasquez Kubernetes (K8s) Infrastructure Connectivity for the Modern Data Center - by Camillo Rossi Isovalent Enterprise with Cisco ACI & Nexus White Paper During Cisco Live, we also announced the release of a new 40-page design guide that explains how to integrate the Isovalent Enterprise Platform with Cisco ACI and Nexus 9000 fabrics. This is the result of a close collaboration between Isovalent and Cisco ACI/Nexus experts. The "Designing Isovalent Enterprise for Cisco ACI & Nexus Guide" is now available. The guide offers practical guidance for bringing eBPF-powered networking, security, and observability to Kubernetes environments running on Cisco infrastructure. It walks through how to connect and secure dynamic cloud-native workloads while maintaining the visibility and control network engineers expect from Cisco platforms. In this draft release, you'll find: Deployment considerations and architectural patterns Guidance on multi-tenancy, Zero Trust, and identity-aware policies Techniques to optimize networking performance for AI and other demanding applications Operational best practices that align with Cisco tooling and workflows If you have any questions about this document - including suggestions for improvements! - or would like assistance implementing the recommended design, get in touch! For a sneak peek into the guide, check out some of the screenshots below: An Evening on the Bay The plan for our exclusive ancillary event was to invite a select group of Cisco Live attendees on a private cruise to enjoy curated cocktails, delicious bites, and stunning sunset views - all while mingling with cloud-native peers and the Isovalent team. Unfortunately, thanks to the aforementioned June Gloom, the sunset never showed up. But we hope our guests still enjoyed the experience as we navigated around San Diego Bay and shared a relaxed evening together on the water. New website! Last but not least, Cisco Live marked the launch of the updated Isovalent.com website! We love the fresh look of the new website - we hope you like it too! Compared to the humble beginnings of Isovalent.com in 2018, it’s quite the improvement 😅 Thanks for reading and see you next year, in Amsterdam (February 9-13, 2026) or in Las Vegas (May 31 - June 4, 2026). Cisco Live Media Coverage You can read the coverage of the Isovalent Load Balancer launch across these various publications: TechTarget: Cisco Isovalent Load balancer takes aim at Broadcom’s VMware Techstrong.IT: Isovalent Adds Load Balancer to eBPF Networking Portfolio InfoWorld: Cisco Live: AI will bring developer workflow closer to the network NetworkWorld: Cisco capitalizes on Isovalent buy, unveils new load balancer Cybernews: Cisco is also quietly stepping back into the load-balancing arena The Register: Cisco returns to load balancing market as it chases VMware refugees