Skip to main content
Versa Networks

VSIA, VSPA, and VSPIA Behavior Changes Between Titan Releases 11.0 and 11.2

Versa-logo-release-icon.png For supported software information, click here.

Titan Portal introduces version 1 and version 2 for Versa Secure Internet Access (VSIA), Versa Secure Private Access (VSPA), and Versa Secure Private and Internet Access (VSPIA) to maintain the existing behavior and to implement new behavior. Version 1 maintains the behavior of Titan Portal before Release 11.2, and version 2 implements the behavior changes for Releases 11.2 and later.  Existing organizations remain on version 1, and new organizations default to version 2.

VSIA, VSPA, and VSPIA Behavior, Version 1 (Before Release 11.2)

Version 1 maintains the existing behavior of of Titan Portal before Release 11.2, as follows:

  • Gateway and multitenant remote access VPN (RAV) support is maintained.
  • VSIA—Endpoint client is not supported.
  • VSPA—SD-WAN steering is not available.
  • VSPIA—Combines both VSIA and VSPA.
  • Tunnel selection is based on the subscription tier:
    • Split tunnel is available for all license tiers.
    • Full tunnel is available for professional or secure app optimization license tiers.
  • Multitenant remote access VPN—Client steering, client security and endpoint information profile (EIP) are supported.

VSIA, VSPA, and VSPIA Behavior, Version 2 (Releases 11.2 and Later)

Version 2 refines the SASE gateway tiering and feature allocation. The professional tier includes full unified threat management (UTM) and unrestricted app access, and the essential tier retains baseline coverage. Multitenant setups now support the Versa endpoint client for remote access VPN (RAV) with full-tunnel connectivity, improving transparency in client and UTM availability. 

Gateway Behavior Changes

The following table shows the services supported on the Versa endpoint client for a SASE gateway:

  • VSIA—Endpoint client with full tunnel is available.
  • VSPA—Endpoint client only with split tunnel and SD-WAN steering.
  • VSPIA—Split tunnel and full tunnel are available.
Features VSIA VSPA VSPIA
EIP Yes Yes Yes
Digital Experience Monitoring (DEM) Yes Yes Yes
Application steering Exclude route (10 applications) Include route (10 applications) Yes
Full tunnel Yes   Yes
Split tunnel   Yes Yes
SD-WAN—Device configuration, not under endpoint client Yes Yes Yes
Private prefixes No—0.0.0.0/0 Yes—Default but allows the user to edit Yes

Multitenant Remote Access VPN Behavior Changes

For multitenant remote access VPN, VSIA with full tunnel is applicable. IP, DEM, application steering, and client security are not supported.

Gateway and Multitenant Behavior Based on License Types

Version 1

Gateway Type Gateway Option Gateway Tier Behavior
SASE Gateway (Private) VSIA Essential
  • VSA not available
  • UTM not available
SASE Gateway (Private) VSIA Professional
  • VSA not available
  • UTM available
SASE Gateway (Private) VSPA Essential
  • VSA available with split tunnel
  • UTM not available
SASE Gateway (Private) VSPA Professional
  • VSA available with both split and full tunnel
  • UTM available
Multitenant VSIA Essential
  • VSA not available
  • UTM not available
  • Secure app optimization not available
Multitenant VSIA Professional
  • VSA not available
  • UTM available
  • Secure app optimization not available
Multitenant VSIA Secure App Optimization
  • VSA not available
  • UTM available
  • Secure app optimization available
Multitenant with RAV VSIA and VSPA Essential
  • VSA available only with split tunnel
  • UTM not available
  • Secure app optimization not available
Multitenant with RAV VSIA and VSPA Professional
  • VSA available with both split and full tunnel
  • UTM available
  • Secure app optimization not available
Multitenant with RAV VSIA and VSPA Secure App Optimization
  • VSA is available with both split and full tunnel
  • UTM available
  • Secure app optimization is available

Version 2

Gateway Type Gateway Option Gateway Tier Behavior
SASE Gateway (Private) VSIA Essential
  • Endpoint client available with full tunnel
  • UTM not available
  • Supports a maximum of 10 applications
SASE Gateway (Private) VSIA Professional
  • Endpoint client available with full tunnel
  • UTM available
  • No restriction in application support
SASE Gateway (Private) VSPA Essential
  • Endpoint client available only with split tunnel
  • UTM not available
  • Supports a maximum of 10 applications
SASE Gateway (Private) VSPA Professional
  • Endpoint client available only with split tunnel
  • UTM available
  • No restriction in application support
Multitenant VSIA Essential
  • Endpoint client not available
  • UTM not available
  • Secure app optimization not available
Multitenant VSIA Professional
  • Endpoint client not available
  • UTM available
  • Secure app optimization not available
Multitenant VSIA Secure App Optimization
  • Endpoint client not available
  • UTM available
  • Secure app optimization available
Multitenant with RAV VSIA Essential
  • Endpoint client available with full tunnel
  • UTM not available
  • No EIP, DEM, application steering, or client security
  • Secure app optimization not available
Multitenant with RAV VSIA Professional
  • Endpoint client available with full tunnel
  • UTM available
  • No EIP, DEM, application steering, or client security
  • Secure app optimization not available
Multitenant with RAV VSIA Secure App Optimization
  • Endpoint client available with full tunnel
  • UTM available
  • No EIP, DEM, application steering, or client security
  • Secure app optimization available

Supported Software Information

Releases 11.2 and later support all content described in this article.

  • Was this article helpful?