You can insert the security VNF into both the VLAN as well as routed interface.


Ensure that you have created a security VNF and configured the settings. See Configure Security VNF without HA and Configure Security VNF with High Availability.

Map the segments with service VLANs to enable VNF insertion into the VLANs. See Define Mapping Segments with Service VLANs.


  1. In the Enterprise portal, click Configure > Edges.
  2. In the Edges page, either click the Device Icon next to an Edge or click the link to an Edge and click the Device tab.
  3. In the Device tab, scroll down to the Configure VLAN section.
  4. Click the Edit link of the VLAN to which you want to insert the VNF.
  5. In the VLAN window, select the VNF Insertion checkbox to insert the VNF into VLAN. This option redirects traffic from a specific VLAN to the VNF.
  6. Click Update VLAN.


The Configure VLAN section displays the status of the VNF insertion.

You can also insert the VNF into Layer 3 interfaces or sub-interfaces. This insertion redirects traffic from the Layer 3 interfaces or subinterfaces to the VNF.

If you choose to use the routed interface, ensure that the trusted source is checked and WAN overlay is turned off on that interface. For more information, see Configure Interface Settings.