The latest version of IP Fabric's network assurance platform models cloud-native networking and security constructs as first-class objects in the digital twin.
Network assurance is critical to modern IT operations, but sophisticated hybrid environments create visibility gaps that impact troubleshooting, compliance validation and change management. As enterprises layer cloud services alongside traditional networks, multiple vendors are working to solve this challenge, and among them is IP Fabric.
The company had multiple releases in 2025 that expanded automation as well as discovery capabilities. To kick off the new year, IP Fabric 7.9 debuted this week, providing expanded capabilities for Azure and Google Cloud Platform environments. The update adds discovery and path analysis for cloud-native security constructs including Azure Firewall, Private Link, Private Endpoints and multi-project GCP topologies. The release also extends IPv6 path analysis across dual-stack environments and introduces API scalability improvements designed to support autonomous network operations.
“With many new clients coming on board, including a number from Fortune 50, we’re seeing more teams going beyond automation, and even starting down the path towards autonomous network operations,” Pavel Bykov, CEO and co-founder of IP Fabric, told Network World. “Digital twin data models provide context that is critical to the success of these initiatives at every stage.”
Closing the cloud visibility gap
Organizations have been struggling with the challenge of hybrid visibility for years, and vendors including IP Fabric have already deployed solutions for enterprises.
Bykov noted that his company’s previous releases provided foundational cloud coverage to help teams understand cloud networking in the context of the full environment. Version 7.9 extends that foundation by modeling cloud-native networking and security constructs as first-class objects in the digital twin.
The update adds discovery for Azure Firewall instances, Private Link services and Private Endpoints. On the GCP side, the platform now supports multi-project discovery and models GCP Interconnect handoffs. These additions allow the platform to trace traffic flows through cloud security boundaries and private connectivity paths.
Multicloud and hybrid network viability has also been extended to include IPv6 path analysis, helping teams reason about connectivity in dual-stack and hybrid environments. This capability addresses a practical challenge for enterprises deploying IPv6 alongside existing IPv4 infrastructure. Network teams can now validate that applications can reach IPv6 endpoints and identify segments where IPv6 connectivity breaks down. The platform models both protocols within the same digital twin, showing how traffic transitions between IPv4 and IPv6 segments.
According to Bykov, platform engineering groups will now be able to visualize complex application workloads from multiple dimensions. That includes the implications of security and advanced routing policy on applications, all the way up to the point of termination within the enterprise.
The cloud abstraction problem
One of the reasons why hybrid visibility for networks can be an issue is because cloud providers deliberately abstract infrastructure complexity from users. Azure Firewall delivers packet filtering as a managed service without exposing the underlying compute or network resources. Private Link creates connectivity paths without requiring customers to understand the routing mechanics.
This abstraction serves a purpose. It allows teams to consume network functions without managing physical infrastructure. But it creates a visibility problem for operations teams who need to understand how these functions affect application traffic.
IP Fabric’s approach is to model the control plane behavior without exposing the underlying implementation. The platform represents what Azure Firewall does to traffic without attempting to map Microsoft’s internal infrastructure. It shows how Private Link affects connectivity without revealing the provider’s routing fabric.
“Abstraction is vital to be able to operate complex infrastructure, and it’s a major appeal that a specific network or security function can be used without having to deal with the underlying complexity,” Bykov explained. “However, that function itself makes a decision about the traffic, affecting the application and that is the control element that the customer is interested in.”
Compliance use case: PCI validation across hybrid infrastructure
From a practical perspective, there are some very specific ways in which fragmented visibility can impact an enterprise’s operations.
One particular issue is that of compliance. Bykov noted that IP Fabric has been working with a large financial company to help them with their Azure migration. The company needed to ensure that cloud-based firewalls enforced the same security policies as on-premises systems to avoid compliance violations, particularly PCI-DSS (Payment Card Industry Data Security Standard).
“PCI adherence is a main concern for them, as it is for any company that accepts credit card information,” Bykov explained. “They wanted to make sure their cloud firewalls adhere to the same policies as their on-prem firewalls, or they could face $100,000 per PCI incident as well as increased transaction and legal fees.”
He noted that using IP Fabric’s latest release, enterprises now have visibility for cloud network devices like firewalls, as well as for native cloud constructs like projects and serverless services.
The platform’s ability to model Azure Firewall configurations alongside on-premises firewall policies allows the compliance team to validate rule consistency across both environments from a single interface.
Why hybrid pathing matters more than the architecture debate
The discussion around hybrid infrastructure often frames it as a transitional state or architectural compromise. Bykov rejects this framing entirely.
“What is there, other than hybrid?” he said. “Hybrid is definitely the way. It’s important to have a heterogeneous and hybrid environment that serves the needs of the client.”
The rationale is practical. Different workloads have different requirements for latency, data residency, cost and performance. Cloud excels for some use cases. On-premises infrastructure remains optimal for others. The network exists to deliver traffic between these environments regardless of where workloads run.
“We always must remember that the network is there to fundamentally deliver traffic from point A to point B, serving the application,” Bykov said. “It’s the same as why there is no single best programming language for software. Each is better suited for different applications.”
Version 7.9 addresses hybrid pathing through enriched metadata for interconnection technologies. The platform now models the specific mechanisms that create connectivity between environments: Azure ExpressRoute circuits, GCP Interconnect attachments and the BGP sessions that exchange routes between domains.
This metadata allows the platform to trace how traffic transitions from enterprise routing protocols into cloud virtual networks. It shows which routes are advertised across the boundary, which peering points carry specific traffic flows and how routing policy affects path selection. Platform engineering teams can now visualize complete application workflows from on-premises databases through cloud security controls to application endpoints.
The hybrid boundary represents a concentrated risk point. While failures at these handoffs are less frequent than issues within a single domain, the blast radius is larger. A misconfigured route advertisement or failed interconnect affects all traffic between environments.
“From experience it’s not the usual place for issues, but when the problem happens at the handoff, it can be severely impactful or create a critical risk, since any failure impacts a significant footprint,” Bykov said. “If the problem is finding a ‘needle in a haystack,’ we want to make sure we’re looking through the entire haystack.”




