Versa Secure SD-WAN features
Versa Secure SD-WAN focuses on these key capabilities:- SD-WAN and Secure Access Service Edge (SASE) — A single platform with a best-of-class security offering. For more information, see Securing the Network with SASE.
- One software stack — A single-pipeline integrated architecture for security, advanced networking, robust analytics, and automation.
- Cloud access security broker (CASB)
- Next-generation firewall (NGFW)
- Secure web gateway (SWG)
- Zero trust network access (ZTNA)
Deployment considerations
This section provides an overview of the MVE deployment options and features.SD-WAN vendors
MVE is integrated with Versa Secure SD-WAN, which uses Versa’s Director console to create the private overlay network. For information about all supported on the MVE platform, see the Megaport Virtual Edge (MVE) product page.MVE locations
For a list of global locations where you can connect to an MVE, see Megaport Virtual Edge Locations.Sizing your MVE instance
The instance size determines the MVE capabilities, such as how many concurrent connections it can support. To size your MVE correctly, consult the vendor’s sizing documentation to ensure it aligns with the number and type of features you plan to enable. When choosing an MVE instance size, keep in mind these items:- Any increase on the network data stream load can degrade performance. For example, establishing secure tunnels with IPsec, adding traffic path steering, or using deep packet inspection (DPI) can affect the maximum throughput speed.
- Future plans to scale the network.
- In the , go to the Services page.
- Click Add Services, then select MVE.
- Select Versa FlexVNF.
- Select the software version.
- Click Next.
- Select an MVE location. Select a location geographically close to your target branch and/or on-premises locations. You can use the Search field to find the Port name, Country, Metro City, or address of your destination Port. You can also filter by diversity zone.
-
A list of available instance sizes appear based on the selected location. Available sizes are highlighted in green and labeled Available. The sizes support varying numbers of concurrent connections, and individual partner product metrics vary slightly.
If the MVE size you want is not in the list, then there is not enough capacity at the selected location. You can either select another location with enough capacity or contact your Account Manager to discuss requirements.
- You can provision another MVE instance, add it to your overlay network, and split the workload between the two MVEs.
- You can provision a larger MVE instance, add it to your overlay network, migrate connections from the old MVE to the new larger MVE, and then retire the old MVE.
Security
MVE provides secure capacity to and from your internet-enabled branch locations, to any endpoint or service provider on the Megaport SDN. CSP-hosted instances of partner SD-WAN products route critical traffic across the Megaport SDN, reducing internet dependence. Traffic remains encrypted and under your policy control while traveling across the Megaport SDN, to or from, MVE. Versa Secure SD-WAN includes access to a comprehensive security feature: . Versa on MVE natively supports SASE and SD-WAN services. For more information, see Securing the Network with SASE.Licensing
You bring your own Versa (Director) SD-WAN license for use with MVE. It is your responsibility to have the appropriate licenses for the SD-WAN endpoints created on the Megaport network.VLAN tagging
Megaport uses to differentiate VXCs and MVEs on a host hardware system. The tenant MVE receives untagged traffic for the internet-facing link, and single-tagged 802.1Q traffic for VXCs toward other destinations on the Megaport network (such as CSP on-ramps or other MVEs). For more information, see Configuring Q-in-Q.vNICs
Each MVE can have up to five vNICs. An MVE is created with one vNIC by default. You can add up to four more, making a total of five. Before specifying the number of vNICs on your MVE:- Be aware that the number of vNICs cannot be changed after an MVE has been ordered. Decide in advance how many vNICs to specify when you create the MVE.
- Consult your service provider to make sure that functionality won’t be affected if you add a vNIC.
If you need to change the number of vNICs after an MVE has been ordered, you will have to cancel and re-order the MVE.