- Dynamic network extension — Enables flexible and on-demand expansion of network infrastructure.
- Scalable connectivity — Supports varying and growing traffic demands across different locations.
- Secure connections — Delivers reliable and protected communication between branches, data centers, and clouds.
- Hardware reduction — Eliminates the need for physical network hardware and simplifies deployment and management.
- 6WIND Virtual Service Router (VSR)
- Anapaya
- Aruba EdgeConnect SD-WAN
- Arista VeloCloud SD-WAN
- Aviatrix Secure Edge
- Check Point CloudGuard
- Cisco
- Deciso OPNsense
- F5 BIG-IP Virtual Edition
- Fortinet FortiGate
- Juniper
- Netskope One SD-WAN
- Palo Alto Networks Prisma SD-WAN
- Palo Alto Networks VM-Series NGFW
- Peplink FusionHub
- Versa Secure SD-WAN
Virtual Firewall as a Service (FWaaS) with MVE
MVE is a cloud-based security solution that delivers firewall capabilities as a service. You can deploy NGFW using Fortinet, Palo Alto, and Cisco. Key benefits of MVE FWaaS:- Dynamic deployment — Firewalls can be deployed flexibly and strategically.
- Consistent security — A uniform, distributed security posture across all locations.
- Secure connectivity — Fast and secure data flow between clouds, branches, and remote sites.
- Hardware reduction — Eliminates the need for physical firewall appliances.
- Simplified management — Streamlines firewall, network, and internet management.
- Flexible licensing — Supports Bring Your Own License (BYOL) for firewalls.
- Advanced security features — Includes intrusion prevention, deep packet inspection, and secure web filtering.
Use cases of FWaaS with MVE
Cloud and hybrid security:- Centralizing firewalls — Centralized firewalls protect multicloud traffic.
- Reducing license costs — License reduction via centralized cloud firewalls.
- Optimizing multicloud security — Focus multicloud interconnection security instead of securing each cloud in isolation.
- Secure remote access — Protect traffic originating from remote users and branch offices.
- Decentralized security — Shift away from on-premises physical firewalls.
- Improve scalability and flexibility — Distributed firewalls offer scalability and flexibility in managing security across geographically dispersed locations.
- Hardware reduction — Eliminate the need for physical firewall appliances.
- Centralized firewall management — A single point of control for managing firewalls.
- Consistent global policies — Enforce uniform security policies across all locations.
- Strategic control point — Position the firewall management system between data centers (DCs), Cloud Service Providers (CSPs), and the internet.
SD-WAN gateways with MVE
MVE enables quick deployment of SD-WAN and other network services without physical hardware. MVE deploys virtual network functions at the edge of the Megaport network, enhancing the speed and security of network traffic to cloud and branch locations. SD-WAN centralizes and simplifies WAN management by virtualizing networks, allowing for flexible transport, automated routing, and real-time performance monitoring. Megaport SDN is a global private on-demand network. MVE integrates with Megaport internet to allow SD-WAN appliances to connect to the Megaport SDN via the internet. Reliance on the internet is minimized to a few hops. Megaport SDN acts as a bridge to Megaport’s private network and ensures low latency. In the diagram below, once traffic enters the Megaport SDN through an MVE, it remains within Megaport’s secure and private infrastructure, which optimizes network reliability. Key benefits of MVE SD-WAN:- Global, flexible connectivity — Global, flexible connectivity without private circuits.
- Optimized SD-WAN termination — Localized traffic via metro MVE edge points. Connect via Cross Connects, DCs, or the internet.
- Direct cloud and SaaS access — Direct access to clouds, , data centers, and the Megaport Marketplace.
- Flexible, pay-as-you-go pricing — Simplified pay-as-you-go cost management including IP address usage, internet access, and a connection to the internet that terminates the tunnel between the MVE and customer-provided equipment at the branch.
- Enhanced security with SASE — NFV with leading SD-WAN partners for SASE.
- Fast Portal provisioning — Rapid deployment using the Megaport Portal.
Virtual router with MVE
MVE integrates virtual router capabilities from leading vendors such as Cisco, Fortinet, and 6WIND. It allows you to deploy and manage virtual network functions (VNFs) on demand, offering flexibility and control over network routing, security, and optimization. Unlike the Megaport Cloud Router (MCR), MVE offers vendor-specific CLI access and advanced features, including VPN, QoS, firewall, NAT, and SD-WAN, enabling consistent functionality across both virtual and physical platforms. Key benefits of MVE virtual router:- Multivendor support — Deploy virtual routers from Cisco, Fortinet, 6WIND, and other providers with their software feature sets.
- On-demand provisioning — Scale quick virtual network functions in global Megaport locations.
- Enhanced control — CLI access for direct configuration and advanced routing options beyond what MCR offers.
- Edge connectivity — Seamless integration with SD-WAN, public clouds, and private networks for optimized traffic flow.
- Security and performance — Leverage vendor-specific security policies, QoS, and traffic management.
SCION integration with Anapaya and MVE
MVE supports integration with Anapaya to enable SCION (Scalability, Control, and Isolation On Next-Generation Networks). SCION is a next-generation internet architecture that provides stronger path control, isolation from failures, and explicit trust information for end-to-end communication. Through Anapaya, Megaport MVE can deliver:- Cryptographically verified path segments
- Multi-path discovery and failover
- Route selection based on performance, trust, or geographic location
- Trusted networks — SCION networks are organized into autonomous systems (AS) and grouped into trust domains (ISDs) with defined trust policies. Each ISD can establish its own trust roots and maintain its own public key infrastructure (PKI), cryptographically verifying participating autonomous systems (AS) and reducing reliance on third-party PKIs.
- Fast multi-path discovery and failover — SCION discovers path segments (hops) in advance and assembles available paths to destinations, allowing quick switching between paths and simultaneous use of multiple paths. This increases resilience and protects against outages or denial-of-service attacks.
- Path validation — Every hop on a SCION path is cryptographically verified, which protects against route leaks, hijacks, and IP address spoofing, and ensures stronger validation of traffic.
- Geofencing for data sovereignty — Users can select preferred paths for their data based on performance, trust, or geographic attributes. This supports compliance with data sovereignty requirements.
- Scalability and interoperability — SCION is compatible with existing internet infrastructure and protocols. SCION-enabled devices can connect through SCION gateways without requiring changes to internal network infrastructure.
Juniper Session Smart Router (SSR) with MVE
Juniper SSR on MVE transforms SD-WAN deployment by eliminating the complexity of traditional tunnel-based overlays. Using Secure Vector Routing (SVR), Juniper SSR creates dynamic, session-aware, and highly secure connections that simplify network management while improving application performance and security across branch offices, remote sites, and multicloud environments. The SSR deploys Juniper’s advanced, software-defined routing platform on MVE as a virtual router and SD-WAN gateway, managed through the Juniper Mist platform. By removing the need for VPN tunnels entirely, Juniper SSR reduces operational burden while delivering enhanced security and application performance across Megaport’s global private network. Key benefits of Juniper SSR on MVE:- Secure Vector Routing (SVR) — Eliminates VPN tunnel complexity, replacing traditional overlays with session-aware routing, which reduces operational overhead and improves network reliability.
- Session-aware routing — Routes traffic based on application sessions rather than network topology, providing dynamic path selection and optimized performance.
- Application-centric approach — Simplifies network configuration by aligning routing policies with application requirements instead of complex network constructs.
- Enhanced security — Delivers authenticated, session-based security without the overhead and vulnerabilities of traditional VPN tunnels.
- Juniper Mist cloud management — Centralized management, automation, and analytics through the Juniper Mist platform for streamlined operations across distributed locations.
- Seamless multicloud connectivity — Extends consistent policies and secure connectivity across branch offices, remote sites, and cloud environments over Megaport’s private SDN.
Juniper vSRX with MVE
Juniper vSRX on MVE delivers advanced firewall and security capabilities through a virtualized . The vSRX provides the same security features as physical SRX Series platforms in a virtual form, enabling flexible deployment across Megaport’s global private network. With vSRX, you get stateful firewall protection, intrusion prevention, application visibility, and VPN capabilities. Deploying vSRX on MVE lets you secure traffic between branch locations, cloud environments, and data centers without physical hardware. Key benefits of Juniper vSRX on MVE:- Flexible deployment — Deploy Juniper NGFW security without physical appliances, shipping delays, or rack-space requirements.
- Stateful firewall protection — Provides deep packet inspection and application awareness for comprehensive threat defense.
- Intrusion prevention — Detects and blocks network threats with integrated intrusion detection and prevention.
- Simplified management — Optional Juniper Mist integration for centralised visibility and control.