Netskope Publisher - Specifications
Netskope Publisher
This page describes the deployment and configuration items for Netskope Publisher by Netskope. The VNF is delivered from the Publisher image and supports single and dual deployment modes (dual mode deploys two virtual devices); the specification does not imply automatic failover or high-availability.
Flavors
The available sizes are shown in the flavor table below.
| Standard | |
|---|---|
| Medium | 4 vCPU 8 GB Mem 64 GB Disk |
| Large | 8 vCPU 16 GB Mem 64 GB Disk |
Supported flavor identifiers mentioned in the blueprint include std1.c4 (4 vCPU, 8 GB RAM, 64 GB disk) and std1.c8 (8 vCPU, 16 GB RAM, 64 GB disk). In dual deployments you may choose a flavor for each virtual device.
Interfaces
The diagram above shows a simplified topology: the Netskope Publisher VM connects to the public Internet via a platform-allocated public IP on #1 - Internet Interface. The optional #2 - MPLS-VPN interface exposes VLAN sub-interfaces (101..108) that can carry VPN entries and optional BGP per VLAN.
Common interface behaviour
- The Public IP address shown for the Internet interface is a platform-generated output and is not provided by the customer during creation.
- VLAN sub-interfaces on #2 - MPLS-VPN interface accept VPN entries and optional routing controls; common fields are documented once below and apply to each configured VLAN.
#1 - Internet Interface
- Role: connect the VM to the public Internet.
- Public IP: a platform-allocated IPv4 address is attached and exposed in deployment outputs (no customer input required to allocate this address).
- Mandatory: yes for Internet connectivity.
#2 - MPLS-VPN interface (optional)
- Role: connect to operator MPLS/VPN services using VLAN sub-interfaces (101..108).
- VLAN sub-interfaces: each VLAN accepts a VPN list (one to 99 entries). Each VPN entry includes a VPN Name (alphanumeric and - or _) and a VPN role (one of: any-to-any, client, server).
- Addressing: provisioning may request the VLAN subnet (CIDR) and gateway address; these values are provided as part of the VLAN configuration during provisioning.
- BGP (per VLAN): optional. See Routing / BGP section for details.
Routing / BGP
- Enable BGP: optional and updatable per VLAN (boolean, default: false). When not enabled, no BGP-specific configuration is applied by the service form.
- AS prepend: optional integer (1..6). The blueprint notes this parameter is intended for backup VM scenarios only; provide a value only when operational procedures require it. Do not interpret this parameter as indicating automatic failover behaviour.
Virtual device parameters
- VM name (mandatory): hostname-like string (pattern: letters, numbers and hyphen; max length 20). Provide a name that follows the constraint.
- VM image (mandatory): select from supported images. The blueprint lists supported images such as ubuntu-22.04.5-server-cloudimg-amd64-20251203.
- VM flavor (mandatory): choose std1.c4 or std1.c8 to set compute/memory/disk sizing.
- VM AS number (optional): AS number for BGP if BGP is planned (range: 1..4294967295).
Service specific parameters
Service-level parameters are requested during provisioning and apply to the whole VNF, not to a single VM interface.
- Registration token generated (mandatory): authentication token used by the Publisher bootstrap process to register the device with the Netskope control plane. Obtain this token from the Netskope account process and provide it in the provisioning UI. Do not publish real tokens; enter them securely in the provisioning form.
- Username (mandatory): initial administrative username created on the VM by cloud-init. Provide this value in the provisioning form.
- User password (mandatory): password for the initial user. Provide securely in the provisioning UI; do not publish example passwords.
- Root password (mandatory): root account password set during provisioning. Provide securely in the provisioning UI; do not publish example passwords.
Software device versions
Below are the software image versions available for Netskope Publisher.
- 22.04.5
Platform-generated outputs
- Public IP address: the IPv4 address allocated by the platform and attached to #1 - Internet Interface. This address appears in deployment outputs for external connectivity and DNS purposes.