VeloCloud VCE - Specifications
Overview
This page describes the main deployment and configuration aspects of VeloCloud VCE. The VCE delivers SD‑WAN gateway (Edge) functions and supports both single and dual deployment modes (single VM by default; dual deploys two virtual devices). The sections below cover flavors and software, numbered interfaces, service parameters, routing hints and platform-generated outputs.
Flavors
Choose the compute profile for the VCE VM using the available flavors below. DPDK and standard flavors are offered to match throughput requirements.
| Standard | DPDK | |
|---|---|---|
| Small | 2 vCPU 8 GB Mem 64 GB Disk | - |
| Medium | 4 vCPU 16 GB Mem 64 GB Disk | 4 vCPU 16 GB Mem 64 GB Disk |
| Large | 8 vCPU 32 GB Mem 64 GB Disk | 8 vCPU 32 GB Mem 64 GB Disk |
In a dual deployment you may select a flavor for each virtual device.
Interfaces
The diagram above is a simplified view of the VCE topology: a single VeloCloud VCE virtual device exposes three numbered interfaces. #2 - MPLS‑VPN interface supports VLAN sub-interfaces (VLANs 101..108) and is optional; #3 - Internet Interface GE3 is the Internet uplink and is associated with a platform-assigned public IPv4 address. VLANs are grouped in the diagram to keep the topology readable.
All interfaces are attached per virtual device. The sections below explain the customer-facing role of each interface and the configuration fields you will see in the UI.
#1 - Fake Interface GE1
This is an informational interface. No customer parameters are required or expected for this interface.
#2 - MPLS-VPN interface (optional)
Used to connect the VCE to an MPLS‑VPN environment via VLAN sub-interfaces. VLANs 101..108 are supported as sub-interfaces; each VLAN can carry one or more VPN entries.
- VPN list: add one or more VPN entries per VLAN (min 1, max 99). Each entry includes VPN Name (string; allowed characters: letters, digits, hyphen, underscore) and an optional VPN role (one of: any-to-any, client, server).
- BGP (per VLAN): BGP is optional and configurable per VLAN. The available fields include Enable BGP (boolean, default: false) and AS prepend (integer 1–6) — the AS prepend value is an advanced option used in specific backup VM scenarios.
Document common VPN parameters once; these apply to VLAN sub-interfaces 101..108.
#3 - Internet Interface GE3
Internet uplink for the VCE. The platform allocates a public IPv4 address and exposes it as a platform-generated output in the UI. The public IP must be allocated in the platform before completing interface configuration where required.
- Public IP address: platform-generated output (not a customer-provided interface parameter).
Software device versions
Below are the software image versions available for this VNF.
- 5.4.0.1
Service parameters
Service parameters are values provided during provisioning and apply at the service/instance level (they are not VM-level or interface IP values). Two service parameters are mandatory for provisioning: the orchestrator address and the activation key. Optional credentials may also be provided for operational access.
-
Velocloud orchestrator FQDN (mandatory, not updatable): fully qualified domain name of the orchestrator the VCE will register to. Provide the FQDN used by your VeloCloud administration (example from the specification: vco211-fra1.velocloud.net).
-
Activation key (mandatory, not updatable): one-time device activation key inserted during provisioning so the VCE can authenticate to the orchestrator (example from the specification: EPKP-US6B-N4RW-HPAV). Provide the activation key exactly as issued.
-
SSH public key (optional, not updatable): paste an SSH public key to permit SSH access to the VM. If provided, it is injected via cloud-init.
-
Admin password (optional, not updatable): initial admin password for first-boot access if you prefer password-based access. Follow the platform password rules (strong password; minimum 12 characters with mixed character classes).
Virtual device parameters
These parameters apply to the virtual device(s) instantiated for the VCE.
- VM name (mandatory, not updatable): hostname used to identify the virtual device. Max length 22 characters; allowed characters typically include letters, digits and hyphen.
- Image (mandatory, not updatable): select the supported software image for the VCE (for example: velocloud-vce-5.4.0.1).
- Flavor (mandatory, not updatable): choose the compute/memory profile from the available flavors shown above.
- VM AS number (optional, not updatable): autonomous system number for BGP when used. Accepts integers in the range 1..4294967295 (2-byte and 4-byte AS numbers supported).
Routing and BGP parameters
The BGP settings are optional and configurable per VLAN/VPN on the MPLS‑VPN interface. When BGP is not enabled for a VLAN, no BGP-specific configuration is applied through that setting.
- Enable BGP: optional boolean to enable BGP for the associated VLAN/VPN (default: false).
- AS prepend: optional integer (1–6) used in AS path manipulation for specific backup VM scenarios.
If you plan to exchange routes via BGP, provide a VM AS number and coordinate configuration with your MPLS provider. The specification does not describe route policies or automatic route advertisement.
Platform-generated outputs
Public IP addresses allocated for the Internet interface are platform-generated outputs. The platform displays the allocated public IP in the UI after allocation; these IP addresses are not customer-provided interface input values.
Licence
Only Bring Your Own Licence (BYOL) type is supported for Fortinet SD-WAN. You need to purchase your software licence with Fortinet sales.
Security group
No default security group configured for Fortinet VNE model.