Virtual Network Functions (VNF) Overview
On IZO™+ Multi Cloud Connect, network functions are delivered virtually as a Virtual Network Function (VNF) hosted on the IZO™+ Multi Cloud Connect platform - a router, firewall, SD-WAN appliance or web-application firewall - rather than as a physical box on your premises that you rack and cable. A VNF sits between your Fabric Port and the cloud in a IZO™+ Multi Cloud Connect Flex solution, and can be either customer-managed or Tata Communications-managed.
What a VNF is
A Virtual Network Function is a virtualised network appliance - the same operating software you would run on a physical device from the same vendor, hosted as software on the IZO™+ Multi Cloud Connect. Deploying network functions this way means there is no hardware to procure, ship, rack or cable: you select the function, vendor, model and size in the TCx Portal, and it is spun up as part of your solution.
VNFs are used with the IZO™+ Multi Cloud Connect Flex service model, where the VNF sits between the Fabric Port and the Cloud VC and applies functions such as routing, security or SD-WAN to the traffic on its way to and from the cloud.
Function types
The following function types (device categories) are available as VNFs:
-
Router - a virtual router for connectivity and routing control between your sites, IZO™+ Multi Cloud Connect and the cloud.
-
Firewall - a virtual next-generation firewall for policy enforcement and inspection.
-
SD-WAN - a virtual SD-WAN edge to bring your SD-WAN fabric into the IZO™+ Multi Cloud Connect.
-
WAF / application security - a web-application-and-API-protection function (available in the Tata Communications-managed model).
The vendors, device models, sizes and software versions available for each function type are listed in the Vendors & Devices section.
Where a VNF sits in a solution
In a IZO™+ Multi Cloud Connect Flex solution the traffic path is: your site --> Fabric Port --> VNF (on IZO™+ Multi Cloud Connect) --> Cloud VC --> cloud provider. The Fabric Port is your entry point into the network; the VNF applies its function; the Cloud VC carries the traffic to the cloud. A Cloud VC connects to the rest of the fabric through a Fabric Port or a VNF or a Tata Cloud Router when cloud to cloud connectivity is required.
Two management models
Every VNF is delivered under one of two models, chosen at ordering:
-
Customer-managed - Tata Communications hosts the VNF (compute plus the installed software image); you own the licence and are responsible for configuration, management and patching.
-
Tata Communications-managed - Tata Communications provides the licence and takes responsibility for configuration, management, patching and renewals.
The two models are compared in detail on Managed vs Customer-Managed VNFs.
Redundancy
A VNF and its connections can be ordered as a single link or as a dual link for high availability. A dual-link edge connection requires two Fabric Ports. Selecting dual connectivity provisions the primary and secondary together.