惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Improve Your Microsoft ExpressRoute Resilience with Megaport Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024 Top 5 Cloud and Networking Announcements From Cisco Live 2024
Comparing the SD-WAN Licensing Needs of Major Vendors
2025-05-14 · via Megaport Blog

By Gary Taylor, Solutions Architect

With more enterprises adopting SD-WAN technology, SD-WAN vendor support can be a key to success. We break down the licensing of eight major SD-WAN vendors.

Whichever SD-WAN vendor you use, the way you deploy is essential to success. When you use Megaport Virtual Edge (MVE), Megaport’s on-demand Network Functions Virtualization (NFV) service, you’ll get compute to host the VNF functionality you require, and Megaport Internet for the management access you need – so you can deploy SD-WAN gateways, virtual routers, and virtual firewalls in minutes.

But the different licensing approaches of different SD-WAN vendors will change exactly how you deploy, including with MVE.

Let’s review the licensing approaches of each of Megaport’s partner SD-WAN vendors.

Table of Contents

Cisco SD-WAN

Cisco DNA Software for Catalyst SD-WAN comprises Cisco DNA Essentials and DNA Advantage, with Cisco DNA Premier license now discontinued.

In order to deploy Cisco SD-WAN using MVE, you can use the DNA Essentials license – although some features like “security” will need the DNA Advantage license. You can see Cisco’s full SD-WAN feature matrix here.

Cisco DNA licenses are categorized into network-stack licenses and DNA-stack add-on licenses. So for the Cisco 8000v Autonomous mode MVE, when you configure a network-stack license you will also need a corresponding DNA-stack add-on license.

It’s worth noting that if you just need routing functionality, then some features are only available within the DNA Advantage license (like “multicast”).

Existing Cisco customers would utilize their current DNA Advantage for installation of MVE. The terms for DNA Advantage are three, five, or seven years.

Please note the new Catalyst Routing Essentials license is only available on Cisco Catalyst 8200 and 8300 Platform Family devices, so isn’t applicable to MVE.

This Cisco guide provides a good overview of the SD-WAN and Routing nomenclature.

As a summary, if you wish to provision Cisco SD-WAN using Megaport, you simply choose the bandwidth needed, the term of the license, and which feature set is required between DNA Essentials and DNA Advantage.

The table below provides an overview of the throughput Mapping and Tiers for the Cisco 8000v platform. Throughput greater than 250 Mbps requires an HSECK9 license.

Cisco throughput mapping and tiers
Cisco throughput mapping and tiers

For more information, refer to the Cisco Catalyst 8000v edge software ordering guide.

How to deploy Cisco with MVE

For further details on how to deploy Megaport Virtual Edge using Cisco, visit our Docs Portal.

Fortinet Fortigate-VM

The Fortinet approach to FortiGate-VM licensing is simply based on the number of virtual CPUs configured in the applicable MVE service, as well as the relevant annual subscription licensing.

FortiGate-VM offers a perpetual licensing option (normal series and V-series) as well as an annual subscription option (S-series). Fortinet has also recently introduced a permanent trial mode with some limitations.

The SD-WAN components of FortiGate and FortiOS don’t need any additional licensing or bundles, but it’s still advised to procure the SD-WAN orchestrator license for easy deployment and management of your edge devices.

FortiOS does not have licensed RAM size restrictions and the entry level MVE includes 8 GB of RAM, so well above the recommended minimum of 2 GB RAM.

From an ordering point of view, you can choose:

  • À la carte
  • Advanced Threat Protection (ATP)
  • Unified Threat Protection (UTP)
  • Enterprise Protection (EP)

ATP, UTP, and EP are bundles and include Forticare Premium Technical Support. Find more info on Fortigate Subscriptions and Bundles here.

For example, for a small MVE with 2 vCPUs, your options would be FG-VM02, FG-VM02V, or FG-VM02S.

The “V” suffix means no virtual domains (VDOMs) by default, and the “S” suffix means it’s a subscription-based license. If a license has no letter at the end, it’s a perpetual license.

For the perpetual or “V” license option, you would then choose the applicable additional security features like Intrusion Prevention System (IPS), antivirus, sandboxing, and others if required.

How to deploy Fortinet Fortigate with MVE

For further details on how to deploy Megaport Virtual Edge using Fortinet Fortigate, visit our Docs Portal.

Versa Secure SD-WAN

Versa offers licenses based on feature set requirements, as well as the bandwidth that the specific device is allowed to consume. Each Versa Operating System (VOS) device that you deploy as customer-premises equipment (CPE) is associated with a license.

Like all vendors, the feature set on offer depends on the specific solution tier with more features increasing the cost of the license.

The breakdown is as follows, with each tier being cumulative:

  • Pro Net: Basic and advanced routing features, which are Layer 2 bridging, carrier-class Layer 3 routing, bridging, Layer 4 security, uCPE, and ZTP.
  • Prime SD-WAN: All Pro Net tier features plus SD-WAN connectivity, application identification (App ID), application policy-based forwarding, and traffic engineering.
  • Prime Secure SD-WAN: All Prime SD-WAN tier features plus next-generation firewall (NGFW) which provides Layer 7 security, SSL proxy (for captive portal), and ADC and TLB (for reverse proxy).
  • Premier Secure SD-WAN: All Prime Secure SD-WAN tier features plus application performance optimization for best application experience and TCP optimization.
  • Premier Elite SD-WAN: All Premier Secure SD-WAN tier features plus unified threat management (UTM).

Bandwidth requirements

In addition to the features needed, the license specifies the amount of bandwidth that can be used. Versa Networks measures bandwidth usage based on the WAN interface; for multiple WAN interfaces, bandwidth is aggregated.

Versa tracks the 95th percentile bandwidth usage, allowing the VOS CPE device to exceed the configured bandwidth 5% of the time.

High Availability (HA)

Versa Networks provides stateful HA synchronization capabilities across active-standby clusters. For any tier you will need NGFW and UTM capabilities, including secure SD-WAN tiers. Bandwidth capacity must match the bandwidth capacity of the underlying SKU on a device. You can learn more in the Versa Docs Portal.

How to deploy Versa Networks with MVE


For further details on how to deploy Megaport Virtual Edge using Versa Secure SD-WAN, visit our Docs Portal.

VeloCloud SD-WAN

Velocloud SD-WAN consists of globally distributed Cloud Gateways as well as Velocloud SD-WAN Edges. MVE hosts edge devices only.

The Velocloud Orchestrator management console is used to create an edge profile and edge device. You then apply this profile to your MVE.

VeloCloud SD-WAN Edge licensing consists of 4 components, namely:

  • bandwidth
  • edge software edition (feature set)
  • gateway regional geolocation
  • term.

Each component is summarized below:

Component

Supported Attributes

Bandwidth

10M, 30M, 50M, 100M, 200M, 350M, 500M, 750M, 1G, 2G, 5G, 10G

Editions

Standard, Enterprise, Premium

Region

North America, Europe Middle East and Africa, Latin America, Asia Pacific

Term

1 year, 3 years, 5 years

Edge licensing allows a customer to link a software subscription to a specific Edge device.

VeloCloud SD-WAN Edition Types

Feature

Standard Subscription

Enterprise Subscription

Premium Subscription

VeloCloud Orchestrator

Dynamic Multi-Path Optimization (DMPO)

Number of Edges supported

Unlimited

Unlimited

Unlimited

Maximum number of data segments

4

128

128

Maximum number of profiles

4

Unlimited

Unlimited

Partner Gateway support

Virtual services orchestration for NGFW deployment on Edges

Routing support

BGP, OSPF

BGP, OSPF, Multicast

BGP, OSPF, Multicast

Cloud Gateway to SaaS and Cloud Security Service (without tunneling)

Cloud Gateway to legacy DCs, IaaS, or Cloud Security Service via tunnels (non-SD-WAN destinations)

Add-on

Add-on

Enhanced Firewall Service (including IDS/IPS, URL Filtering, Malicious IP Filtering)

Add-on

Add-on

Add-on

Hosted firewall logging

Security monitoring dashboard

Direct Edge to Internet/Cloud Security Service (BGP over IPsec)

Automated tunnel setup via API to IaaS or third-party Cloud Security Service

From Edge

From Edge or Gateway

PCI-certified service

Add-on

Add-on

Add-on

Upgradeable to a Higher Edition

N/A

Hub clustering

Gateways as Cloud VPN Hub

Auto VPN setup

Hub to Spoke

Hub to spoke plus dynamic B2B

Hub to spoke plus dynamic B2B

Customizable business and security policy

Path visibility

Last-mile

Last-mile plus site-to-site

Last-mile plus site-to-site

Wired/wireless/LAN/WAN analytics with Edge Intelligence

Add-on

Includes 1 node, additional nodes available as add-on

Includes 2 node, additional nodes available as add-on

Edge Intelligence IoT operational assurance

Add-on

Add-on

Add-on

PKI certificate management

Embedded certificate

of authority (CA)

Embedded CA plus intermediate and external CA

Embedded CA plus intermediate and external CA

Mixed editions

VMware VeloCloud provides the option for either Proof of Concept (POC) or Production Deployments.

POC deployments

If a customer wants to run a POC, then a POC license is available for this purpose with the following attributes:

Attribute

Description

Bandwidth

10G

Editions

POC

Region

North America, Europe Middle East and Africa, Latin America, Asia Pacific

Term

5 years

Production deployments

When an Edge is deployed in a production environment, the license type assigned should align with the software subscription purchased. For example, if the subscription SKU NB-VC100M-PRE-HO-HG-L34S312P-C was purchased for use with the Edge being configured, the correct license type attributes as highlighted would be as follows:

  • Bandwidth: 100M
  • Edition: Premium
  • Term: 1 Year
  • HO: Hosted Orchestrator.

How to deploy Velocloud with MVE

For further details on how to deploy Megaport Virtual Edge using Velocloud SD-WAN, visit our Docs Portal.

HPE Aruba EdgeConnect SD-WAN

Licensing for HPE Aruba EdgeConnect SD-WAN is purchased on a per-gateway basis with options as follows:

  • Term: 1, 3, 5, or 7 years
  • License Type: Foundation, Advanced, or On-Premises (detailed below)
  • Bandwidth: Bandwidth requirements per gateway
  • Optional: “Add Boost” - available in 100 MB and 10 GB of WAN optimization.
  • Optional: “Add Dynamic Threat Defense (DTD)” – for IDS/IPS, additional security-related features may be tied to the DTD license.

HPE Aruba provides three licensing tiers for EdgeConnect SD-WAN deployment: Foundation, Advanced, and On-Premises.

  • Foundation provides a value-centric option, including essential SD-WAN features and advanced NGFW features. It includes Cloud Orchestrator.
  • Advanced provides maximum performance with advanced SD-WAN features and advanced NGFW features. It includes Cloud Orchestrator.
  • On-Premises provides maximum performance for on-premises deployment with advanced SD-WAN features and advanced NGFW features.

Foundation (AAS)

Advanced (AAS)

On-Premises

Bandwidth tiers

3 tiers (100M, 1G, 10G)

20M/50M/100M/200M/500M/1G/2G/Unlimited

20M/50M/100M/200M/500M/1G/2G/Unlimited

BIOs

3 (RealTime, Critical and Default)

7

7

Network segments/VRF

2 (auto-enabled, default, and guest only)

64

64

Routing

BGP, OSPF, Subnet sharing

BGP, OSPF, Subnet sharing

BGP, OSPF, Subnet sharing

Mesh networking

No

Yes

Yes

Multi-region topology

Max 4 regions, 4 hubs/region

Yes

Yes

AppExpress

No (monitor only)

Yes (monitor and steer)

Yes (monitor and steer)

Orchestrator

Cloud Orchestrator Foundation

Cloud Orchestrator Advanced

On-premises

Orchestrator stats retention

24h/7d/1mo (m/h/d)

72h/14d/3mo

Custom

The bandwidth licensing is based on cumulative bandwidth via the WAN port.

How to deploy HPE Aruba with MVE

For further details on how to deploy Megaport Virtual Edge using HPE Aruba EdgeConnect SD-WAN, visit our Docs Portal.

Palo Alto

Prisma SD-WAN

Megaport offers two flavours of Palo Alto SD-WAN to cater for the branch office as well as the data center software model, both supported via MVE:

1. SD-WAN 310xv: for branch offices

2. SD-WAN 7108V: for data centers.

Branch office subscription

You can choose from one of the three options below for the branch subscription (per-device):

  • Small (S): up to 25 Mbps
  • Medium (M): up to 250 Mbps
  • Large (L): up to 2,500 Mbps.

Bandwidth tiers are based on the maximum ingress and egress bandwidth per device. Beyond the S, M, and L license, you can still order the following bandwidth tiers:

  • 25 Mbps
  • 50 Mbps
  • 150 Mbps
  • 250 Mbps
  • 500 Mbps
  • 1 Gbps
  • 2.5 Gbps.

This option also includes the zone based firewall (ZBFW) add-on.

The following optional add-on licenses are available for a device-based branch subscription:

  • WAN Clarity Reporting (WCR): AIOps capabilities and system-generated reports.
  • Clarity Network DVR: Data retention and visibility beyond the default seven days.

1. Per-branch site subscription

Recommended for users with two or more devices per site or HA sites, and based on the following tiers:

  • Small (S): up to 25 Mbps across all ION devices in a branch site
  • Medium (M): up to 250 Mbps across all ION devices in a branch site
  • Large (L): up to 2,500 Mbps across all ION devices in a branch site.

Per-site licenses include ZBFW, DVR, and WCR in the list price.

2. Aggregate bandwidth subscription

This subscription provides the option to purchase an aggregate bandwidth quantity (in Mbps) that can be shared across all branch sites, including HA scenarios.

This includes the ZBFW, DVR, and WCR license add-ons.

All license options are from one year to five years.

Data center subscription

A data center subscription is needed when deploying the MVE SD-WAN 7108V version on the Megaport platform. This covers the features needed for data center sites and supports throughput up to 3 Gbps using 8vCPUs.

How to deploy Palo Alto Prisma with MVE

For further details on how to deploy Megaport Virtual Edge using Palo Alto SD-WAN, visit our Docs Portal.

VM-Series

For the Palo Alto VM-Series MVEs, Megaport supports the Bring Your Own License (BYOL) model.

For PAN-OS versions >10.0.4, this can be delivered as either software NGFW credits (flexible vCPU) or as VM-Series Model (fixed vCPU) licenses.

Full details software NGFW credit options can be found here.

VM-Series Model licenses are available on all PAN-OS versions although greater features and flexible vCPUs are possible on version 10.04 and greater.

The fixed vCPU models and associated vCPU are covered as follows:

  • VM-50 / VM-100 – 2 vCPU
  • VM-300 - 2 / 4 vCPU
  • VM-500 - 2 / 4 / 8 vCPU
  • VM-700 - 2 / 4 / 8 / 16 vCPU.

Security services and/or a Panorama deployment to manage the firewalls come at an additional cost.

How to deploy Palo Alto VM-Series with MVE

For further details on how to deploy Megaport Virtual Edge using Palo Alto VM-Series, visit our Docs Portal.

6WIND VSR

6WIND VSR with Megaport’s MVE provides four licensed network functions:

  1. Virtual Border Router (vBR): Facilitates efficient interconnection between network segments, reducing latency and improving performance. Ideal for connecting with hyperscalers, Internet Exchanges, or upstream service providers.
  2. Virtual Carrier Grade Network Address Translation (vCGNAT): Extends IPv4 address lifespan by enabling multiple users to share one public IP, improving security by hiding internal IPs. Supports NAT44 and NAT64 with DNS64.
  3. Virtual Security Gateway (vSecGW): Provides scalable Layer 3 IPSec VPN connectivity for fixed, wireless, and converged networks, supporting site-to-site or remote user connections.
  4. Virtual L3/L4 Firewall (vFW): Protects against cyber threats while ensuring performance, helping meet regulatory requirements and safeguard data.

To create an MVE, you need a Megaport Portal account with ordering permissions and a valid 6WIND license.

To obtain a trial 6WIND license, submit a request through the 6WIND VSR evaluation page, or contact 6WIND Sales, a reseller, or your Megaport Sales Representative.

How to deploy 6Wind VSR with MVE

For further details on how to deploy Megaport Virtual Edge using 6Wind VSR, visit our Docs Portal.

Aviatrix

Aviatrix provides licensing to users on cloud providers for the customer IDs (licenses) that are needed to access the Aviatrix Cloud Network Controller and Aviatrix Cloud Network CoPilot.

This service also calculates Aviatrix bills based on usage. Full details on the required subscriptions per CSP are detailed here.

How to deploy Aviatrix with MVE

For further details on how to deploy Megaport Virtual Edge using Aviatrix, visit our Docs Portal.

Conclusion

Rarely does a one-size-fits-all approach work for a customer when it comes to deploying an SD-WAN solution. Many have different bandwidth, performance, features, and support requirements driven by various use cases for different business needs.

We hope this primer on the differences in licensing between major SD-WAN vendors helps you better understand the packages you’ll need to select to deploy MVE within your SD-WAN solutions and begin optimizing and modernizing your WAN to reduce operating costs, as well as improve network performance and security.