Netskope Virtual Private Edge (VPE) is a next-generation, cloud-managed on-premises platform that delivers secure connectivity and advanced security services at your network edge, with simplified deployment and minimal operational overhead. With VPE, Netskope services can run inside your data center or your public cloud environments. At this time, Linux KVM and VMWare ESXi are supported. Support for Hyper-V, AWS, GCP and Azure environments will be released soon.
– Secure Web Gateway (SWG) is the only available Netskope service for Virtual Private Edge (VPE) at this time. More services will be available in the future.
Requirements
Before deploying VPE, you must meet all of these requirements:
-
System Requirements: The minimum system requirements for VPE are:
-
16 CPUs
-
32 GB of memory
-
200 GB of storage
-
-
Ingress ports (inbound traffic): The following ingress ports must be permitted through your firewall:
Protocol Port Service TCP 22 SSH UDP 68 DHCP TCP 80 HTTP TCP 443 HTTPS -
Egress ports (outbound traffic): The following egress ports must be permitted:
Protocol Port Service UDP 53 DNS UDP 67 DHCP -
Traffic steering: Traffic must be explicitly steered to VPE using either an explicit proxy configuration or a PAC file.
-
Allowlist: The following Netskope URL must be added to your firewall or proxy allowlist:
*.goskope.com (TCP 443).
Domain Description Port config-<tenant-URL> Netskope uses this domain for configuring updates from the MP to VPE. 443 events.goskope.com
events.govskope.us
events.govskope.caNetskope uses this domain for sending events from VPE to the MP. 443 callhome-<tenant-URL> Netskope uses this domain for sending metrics and events from the VPE-Node to the MP as well as a remote diagnostic channel between both. 443 defupdate.goskope.com This domain is for the Netskope AV signatures update server. 443 downloadmirror.sv5.gopskope.com This domain is for the threat hashfeeds update server. 443 downloadmirror.fr4.goskope.com This domain is for the threat hashfeeds update backup server. 443

