Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Appliances
    Virtual Appliance
    Virtual Private Edge

    Virtual Private Edge

    Note

    This feature is currently in Beta and is controlled by feature flags. Contact your Netskope Account team to enable this feature in your account.
    Secure Web Gateway (SWG) is the only available Netskope service for Virtual Private Edge (VPE) at this time. More services will be available in the future.

    Netskope Virtual Private Edge (VPE) is a next-generation, cloud-managed on-premises platform that delivers secure connectivity and advanced security services at your network edge, with simplified deployment and minimal operational overhead. With VPE, Netskope services can run inside your data center or your public cloud environments. At this time, Linux KVM and VMWare ESXi are supported. Support for Hyper-V, AWS, GCP and Azure environments will be released soon.

    Requirements

    Before deploying VPE, you must meet all of these requirements:

    • System Requirements: The minimum system requirements for VPE are:
      • 16 CPUs
      • 32 GB of memory
      • 200 GB of storage
    • Ingress ports (inbound traffic): The following ingress ports must be permitted through your firewall:
      ProtocolPortService
      TCP22SSH
      UDP68DHCP
      TCP80HTTP
      TCP443HTTPS
    • Egress ports (outbound traffic): The following egress ports must be permitted:
      ProtocolPortService
      UDP53DNS
      UDP67DHCP
    • Traffic steering: Traffic must be explicitly steered to VPE using either an explicit proxy configuration or a PAC file.
    • Allowlist: The following Netskope URL must be added to your firewall or proxy allowlist:
      *.goskope.com (TCP 443).
    DomainDescriptionPort
    config-<tenant-URL>Netskope uses this domain for configuring updates from the MP to VPE.443
    events.goskope.comNetskope uses this domain for sending events from VPE to the MP.443
    callhome-<tenant-URL>Netskope uses this domain for sending metrics and events from the VPE-Node to the MP as well as a remote diagnostic channel between both.443
    defupdate.goskope.comThis domain is for the Netskope AV signatures update server.443
    downloadmirror.sv5.gopskope.comThis domain is for the threat hashfeeds update server.443
    downloadmirror.fr4.goskope.comThis domain is for the threat hashfeeds update backup server.443
    • Deploying Virtual Private Edge
    • Configuring Virtual Private Edge
    In this Topic
    • Virtual Private Edge