Deployment considerations
This section describes MVE deployment options and sizing for Deciso OPNsense. For an overview of OPNsense features, see Deciso OPNsense with Megaport Virtual Edge. For information about all supported on the MVE platform, see the Megaport Virtual Edge (MVE) product page.MVE locations
For a list of global locations where you can connect to an MVE, see Megaport Virtual Edge Locations.Sizing your MVE instance
The instance size determines the MVE capabilities, such as how many concurrent connections it can support. To size your MVE correctly, consult the vendor’s sizing documentation to ensure it aligns with the number and type of features you plan to enable. When choosing an MVE instance size, keep in mind these items:- Any increase on the network data stream load can degrade performance. For example, establishing secure tunnels with IPsec, adding traffic path steering, or using deep packet inspection (DPI) can affect the maximum throughput speed.
- Future plans to scale the network.
- In the , go to the Services page.
- Click Add Services, then select MVE.
- Select Deciso OPNsense.
- Select the software version.
- Click Next.
- Select an MVE location. Select a location geographically close to your target branch and/or on-premises locations. You can use the Search field to find the Port name, Country, Metro City, or address of your destination Port. You can also filter by diversity zone.
-
A list of available instance sizes appear based on the selected location. Available sizes are highlighted in green and labeled Available. The sizes support varying numbers of concurrent connections, and individual partner product metrics vary slightly.
If the MVE size you want is not in the list, then there is not enough capacity at the selected location. You can either select another location with enough capacity or contact your Account Manager to discuss requirements.
- You can provision another MVE instance, add it to your network, and split the workload between the two MVEs.
- You can provision a larger MVE instance, migrate connections from the old MVE to the new larger MVE, and then retire the old MVE.
Security
MVE provides secure capacity to and from your internet-enabled branch locations, to any endpoint or service provider on the Megaport SDN.Licensing
Before you create an MVE in the Megaport Portal, you need user accounts with ordering permissions that provide access to the Megaport Portal. For more information, see Creating an Account. OPNsense is open-source software. Deciso offers optional commercial support subscriptions and the OPNsense Business Edition with additional features and support. For more information, see the Deciso website.VLAN tagging
Megaport uses to differentiate VXCs and MVEs on a host hardware system. The tenant MVE receives untagged traffic for the internet-facing link, and single-tagged 802.1Q traffic for VXCs toward other destinations on the Megaport network (such as CSP on-ramps or other MVEs). For more information, see Configuring Q-in-Q.vNICs
Each MVE can have up to five vNICs. A Deciso OPNsense MVE is created with two vNICs by default:- 0: WAN
- 1: LAN
- You cannot change the number of vNICs after ordering an MVE. Decide in advance how many vNICs to specify when you create the MVE.
- Consult your service provider to verify that adding a vNIC does not affect functionality.
If you need to change the number of vNICs after an MVE has been ordered, you must cancel and re-order the MVE.