VSIA, VSPA, and VSPIA Behavior Changes Between Titan Releases 11.0 and 11.2
For supported software information, click here.
Titan Portal introduces version 1 and version 2 for Versa Secure Internet Access (VSIA), Versa Secure Private Access (VSPA), and Versa Secure Private and Internet Access (VSPIA) to maintain the existing behavior and to implement new behavior. Version 1 maintains the behavior of Titan Portal before Release 11.2, and version 2 implements the behavior changes for Releases 11.2 and later. Existing organizations remain on version 1, and new organizations default to version 2.
VSIA, VSPA, and VSPIA Behavior, Version 1 (Before Release 11.2)
Version 1 maintains the existing behavior of of Titan Portal before Release 11.2, as follows:
- Gateway and multitenant remote access VPN (RAV) support is maintained.
- VSIA—Endpoint client is not supported.
- VSPA—SD-WAN steering is not available.
- VSPIA—Combines both VSIA and VSPA.
- Tunnel selection is based on the subscription tier:
- Split tunnel is available for all license tiers.
- Full tunnel is available for professional or secure app optimization license tiers.
- Multitenant remote access VPN—Client steering, client security and endpoint information profile (EIP) are supported.
VSIA, VSPA, and VSPIA Behavior, Version 2 (Releases 11.2 and Later)
Version 2 refines the SASE gateway tiering and feature allocation. The professional tier includes full unified threat management (UTM) and unrestricted app access, and the essential tier retains baseline coverage. Multitenant setups now support the Versa endpoint client for remote access VPN (RAV) with full-tunnel connectivity, improving transparency in client and UTM availability.
Gateway Behavior Changes
The following table shows the services supported on the Versa endpoint client for a SASE gateway:
- VSIA—Endpoint client with full tunnel is available.
- VSPA—Endpoint client only with split tunnel and SD-WAN steering.
- VSPIA—Split tunnel and full tunnel are available.
| Features | VSIA | VSPA | VSPIA |
|---|---|---|---|
| EIP | Yes | Yes | Yes |
| Digital Experience Monitoring (DEM) | Yes | Yes | Yes |
| Application steering | Exclude route (10 applications) | Include route (10 applications) | Yes |
| Full tunnel | Yes | Yes | |
| Split tunnel | Yes | Yes | |
| SD-WAN—Device configuration, not under endpoint client | Yes | Yes | Yes |
| Private prefixes | No—0.0.0.0/0 | Yes—Default but allows the user to edit | Yes |
Multitenant Remote Access VPN Behavior Changes
For multitenant remote access VPN, VSIA with full tunnel is applicable. IP, DEM, application steering, and client security are not supported.
Gateway and Multitenant Behavior Based on License Types
Version 1
| Gateway Type | Gateway Option | Gateway Tier | Behavior |
|---|---|---|---|
| SASE Gateway (Private) | VSIA | Essential |
|
| SASE Gateway (Private) | VSIA | Professional |
|
| SASE Gateway (Private) | VSPA | Essential |
|
| SASE Gateway (Private) | VSPA | Professional |
|
| Multitenant | VSIA | Essential |
|
| Multitenant | VSIA | Professional |
|
| Multitenant | VSIA | Secure App Optimization |
|
| Multitenant with RAV | VSIA and VSPA | Essential |
|
| Multitenant with RAV | VSIA and VSPA | Professional |
|
| Multitenant with RAV | VSIA and VSPA | Secure App Optimization |
|
Version 2
| Gateway Type | Gateway Option | Gateway Tier | Behavior |
|---|---|---|---|
| SASE Gateway (Private) | VSIA | Essential |
|
| SASE Gateway (Private) | VSIA | Professional |
|
| SASE Gateway (Private) | VSPA | Essential |
|
| SASE Gateway (Private) | VSPA | Professional |
|
| Multitenant | VSIA | Essential |
|
| Multitenant | VSIA | Professional |
|
| Multitenant | VSIA | Secure App Optimization |
|
| Multitenant with RAV | VSIA | Essential |
|
| Multitenant with RAV | VSIA | Professional |
|
| Multitenant with RAV | VSIA | Secure App Optimization |
|
Supported Software Information
Releases 11.2 and later support all content described in this article.
