---
title: "Calico Enterprise 3.0 with Calico Multi-Cluster Management"
source: "https://www.tigera.io/blog/calico-enterprise-3-0-global-network-security-center-for-kubernetes/"
description: "We are thrilled to announce the release of Calico Enterprise 3.0 and our Global Network Security Center, a game-changing solution that provides centralized management for network security across every Kubernetes cluster in your organization."
---

[Company Blog](https://www.tigera.io/category/company-blog/)

# Calico Enterprise 3.0 with Calico Multi-Cluster Management

By [John Armstrong](https://www.tigera.io/blog/author/john-armstrong/) on May 18, 2020 • 4 min read

As our enterprise customers build out large, multi-cluster Kubernetes environments, they are encountering an entirely new set of security challenges, requiring solutions that operate at scale and can be deployed both on-premises and across multiple clouds.

Today we are thrilled to announce the release of Calico Enterprise 3.0 and the availability of Calico Multi-Cluster Management, a game-changing solution that provides centralized management for network security across every Kubernetes cluster in your organization.

## Calico Multi-Cluster Management

Calico Multi-Cluster Management provides a centralized management plane and single point of control for multi-cluster and multi-cloud environments. Calico Enterprise’s centralized control simplifies and speeds routine maintenance, leaving more time for your platform team to address other important tasks.

For example, instead of logging in to 50 clusters one-at-a-time to make a policy change, with a single log-in to Calico Enterprise you can apply policy changes consistently across all 50 clusters. You can also automatically apply existing network security controls to new clusters as they are added.

![Calico Enterprise dashboard showing overall stats and multiple clusters managed from a single view](/app/uploads/2020/05/MCM-Screen-shot_2020_01_31-300x175.png)

Calico Multi-Cluster Management includes centralized log management, troubleshooting with Flow Visualizer, and cluster-wide IDS (intrusion detection). It also provides compliance reporting, and alerts on non-compliance and indicators of compromise. Alerts are sent to SIEMs, including Splunk and Sumo Logic. The extensible architecture will accommodate new capabilities and use cases as the Calico Enterprise platform evolves, and ease the adoption and deployment of features released in future Calico Enterprise versions.

Calico Enterprise 3.0 also includes new capabilities that enable large enterprise organizations to adopt Kubernetes at scale.

## Calico Egress Gateway

New applications and workloads are constantly being added to Kubernetes clusters. Those same apps need to securely communicate with resources outside the cluster beyond a firewall or other control point. Firewalls require consistent IP, but routable IPs are a limited resource that can be quickly depleted if applied to every pod in a namespace.

Calico Enterprise solves this problem by assigning a routable IP to a single pod and designating it as the egress pod. A single firewall rule can be created that enables all pods within a namespace to have access to a resource outside the cluster. This has the added advantage of eliminating the burden of constant firewall change requests.

Now you can enforce egress policies for Kubernetes resources using your existing firewall infrastructure or other IP control point. Platform teams can continue to scale the cluster while preserving the limited number of routable IPs available.

## Extended BGP Visibility and Troubleshooting Tools

Pods may be running business applications that must be accessible to the rest of the network. When your platform team configures Calico BGP peering with the network, thousands of constantly-changing pod IP addresses are added to the fabric. Sudden changes like this can cause unexpected behavior that is difficult to troubleshoot.

The new, extended BGP capabilities in Calico Enterprise are designed to speed troubleshooting.  You now have access to a richer set of metrics to monitor and alert on indicators such as BGP peering. With this information, operators find it easier to correlate network state changes with other events in the cluster. BGP stats include neighbor status, BGP prefixes received/advertised, capabilities received/advertised, and password for authentication.

## Fast Data Path for Service Providers

Latency-sensitive applications like video streaming and VOIP require high QoS (Quality of Service). To accommodate these apps, service providers sometimes deploy dual-homed data paths: a fast data path for latency-sensitive traffic and a second path for operations and management (O&M).

Calico Enterprise Fast Data Path enables the connection of multiple network interfaces to a pod, creating a multi-homed pod that can support multiple IP addresses and operate on more than one subnet. The interface for policy enforcement is user selectable. Fast Data Path is reserved for applications like video streaming and VOIP that need high QoS.  The O&M path is used by Calico Enterprise to monitor and manage clusters. This controls bandwidth consumption by traffic required to manage network policies and clusters.

————————————————-

**[Free Online Training](https://www.tigera.io/events/)**

Access Live and On-Demand Kubernetes Tutorials

[**Calico Enterprise – Free Trial**](https://www.calicocloud.io/home)

Solve Common Kubernetes Roadblocks and Advance Your Enterprise Adoption

[Products](https://www.tigera.io/tags/products/)[Release](https://www.tigera.io/tags/release/)[Announcements](https://www.tigera.io/tags/announcements/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[Technical Blog](https://www.tigera.io/category/technical-blog/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3180 metric#misses=33 metric#hit-ratio=99.0 metric#bytes=1551504 metric#prefetches=0 metric#store-reads=167 metric#store-writes=17 metric#store-hits=161 metric#store-misses=22 metric#sql-queries=34 metric#ms-total=705.21 metric#ms-cache=34.46 metric#ms-cache-avg=0.1883 metric#ms-cache-ratio=4.9 sample#redis-hits=46261811 sample#redis-misses=13043242 sample#redis-hit-ratio=78.0 sample#redis-ops-per-sec=66 sample#redis-evicted-keys=0 sample#redis-used-memory=113355736 sample#redis-used-memory-rss=101806080 sample#redis-memory-fragmentation-ratio=0.9 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=73301 -->
