Skip to main content

Zscaler Private Service Edge - Specifications

Architecture

The Zscaler Private Service Edge is delivered as a single virtual machine per virtual device. The VM boots a CentOS-based image and a ZPA service-edge container is started by the platform. The device exposes three logical interfaces: Internet, Management, and MPLS‑VPN (with VLAN sub-interfaces).

Flavors

Flavors table for Zscaler Private Service Edge
Standard
Small
4 vCPU
8 GB Mem
64 GB Disk
Medium
8 vCPU
16 GB Mem
64 GB Disk

Supported flavors (examples): std1.c4 — 4 vCPU, 8 GB RAM, 64 GB disk; std1.c8 — 8 vCPU, 16 GB RAM, 64 GB disk. In dual deployments you may select a flavor per virtual device.

Interfaces

The diagram shows a single Zscaler Private Service Edge VM with three logical interfaces. #1 - Internet Interface receives a platform-allocated public IP. #2 - Management interface receives a platform-allocated management IP. #3 - MPLS‑VPN interface uses VLAN sub-interfaces (101..108); VLAN 101 is required, VLANs 102–108 are optional.

Common interface behavior:

  • Platform-allocated IPs (Public IP, Management IP) are provisioning outputs — they are not customer inputs during initial creation unless the portal explicitly requests allocation ranges.
  • VLAN sub-interfaces share the same parameter set (VPN list and optional BGP settings). Document common parameters once and then describe per-VLAN notes.

#1 - Internet Interface

  • Role: Connects to the Internet and receives a platform Public IP address shown in the provisioning result.
  • Customer action during creation: none required for the public IP allocation; use the allocated address for any upstream routing or firewall configuration after provisioning.

#2 - Management interface

  • Role: Management connectivity for the VM and a platform Management IP address allocated and shown in the provisioning result.
  • Customer action during creation: none required for the management IP allocation.

#3 - MPLS‑VPN interface

  • Role: Connects the device to the MPLS‑VPN using VLAN sub-interfaces.
  • VLAN 101 is mandatory and must include at least one VPN entry. VLANs 102–108 are optional.
  • For each VLAN sub-interface provide a VPN list (min 1, max 99 items). Each VPN entry requires:
    • VPN Name — short alias (letters, digits, hyphen, underscore; pattern: [a-zA-Z0-9-_]*).
    • VPN role — one of: any-to-any, client, server.
  • BGP on a VLAN sub-interface is optional. When enabled you must provide routing-related values (see Routing and BGP section).

Routing and BGP

The Enable BGP setting is optional and updatable per VLAN sub-interface. When Enable BGP is not selected, no BGP-specific configuration is generated for that sub-interface.

  • VM AS number: the autonomous system number assigned to the VM. This value is required if you plan to enable BGP (range 1..4294967295). It is provided at device level.
  • AS prepend: optional integer (1..6) used to prepend the VM AS number in advertised BGP AS path; the blueprint notes this may be used for backup VM scenarios. Do not assume any automatic failover or redundancy behavior from this setting.

Virtual device parameters

  • VM image: CentOS-Stream-GenericCloud-x86_64-9-latest.x86_64.
  • Flavor: select std1.c4 or std1.c8 as supported sizes.
  • VM name: provide a hostname (max length and pattern enforced in the portal).

Software device versions

Below are the software image versions available for Zscaler Private Service Edge.

  • 9

Service specific parameters

Service-specific parameters are service-level values required during provisioning. They are not VM-level credentials or interface IP addresses and are handled as sensitive inputs when specified.

  • ZPA provision key (ZPA license)mandatory, not updatable, sensitive. This provision key is provided by Zscaler and is passed to the service-edge container so the instance can register with your Zscaler tenant. Obtain the key from Zscaler and enter it in the creation form. The key is stored securely by the platform.

  • Admin passwordmandatory, not updatable, sensitive. The initial administrative user password provisioned by cloud-init. Provide it in the creation form; do not publish it.

  • Root passwordmandatory, not updatable, sensitive. The root account password provisioned by cloud-init. Provide it in the creation form; do not publish it.

  • VM AS number — provided at device level and required when BGP is used. Format: integer between 1 and 4294967295.

Platform-generated outputs

  • Public IP address (for #1 - Internet Interface) — allocated by the platform and displayed in the provisioning summary.
  • Management IP address (for #2 - Management interface) — allocated by the platform and displayed in the provisioning summary.

Licence

Only Bring Your Own Licence (BYOL) type is supported for Fortinet SDWAN. You need to purchase your software licence with Fortinet sales.

Security group

No default security group configured for Fortinet VNE model.

https://help.zscaler.com/zpa