Site to Site IPsec tunnels with 3rd party vendors
DescriptionVersa-110/CSG750/CSG355/CSG365Versa-120/versa 520/CSG770Versa 810/VEP-4600-V910Versa 1000/VEP-4600-V930/CSG1300Versa CSG2500/CSG5000/R7515-V2800
 or 4 core and 8G VM or 8 core and 16G VM or 8 core and 16G VM or 14 core and 32G VM-
Number of IPsec tunnels2501000100020003000


Note: Above numbers are for route based IPsec. Above number gets reduced by 50% for policy based VPN with same number of SA.  3000 IPsec tunnels is supported only starting from 22.1.4 released in August 18, 2025.




Recommendation for Virtual machine (VM):

  • With the same resources(same CPU class/speed, memory, disk) as a bare-metal installation, the performance of VM headend components is about 25 percent less because of the virtualization.
  • On the VM host, you must allocate a dedicated CPU and dedicated memory to the Versa headend VMs. This is called 1:1 provisioning.
  • You must pin the CPU to the VM vCPU.
  • You must disable hyperthreading on the VM host.
  • The preferred NICs are SR-IOV NICs, which provide the best network I/O. A second choice is a VirtIO NIC driver. For VMWare, it is recommended that you use VMXNET3 on all interfaces.