Hats Network | LogoHats Network
Hats Network Services

Hats EPN | SD-WAN as a Service

Hats EPN delivers managed SD-WAN connectivity with traffic segmentation and predictable latency across 16+ PoPs. Multi-site private mesh across 4 continents with 99.99% SLA-backed uptime.

Hats EPN (Enterprise Private Network) provides managed routing or Ethernet transport between customer sites.

Why Managed WAN?

Hats EPN connects multiple sites with separate traffic segments and managed routing. We handle the backbone and agreed edge configuration; your team manages the applications and local networks.

Why Managed WAN?

The comparison below separates the tasks managed by Hats Network from those retained in a customer-operated deployment.

AspectSelf-Built SD-WANHats EPN (Managed)
Setup Time3-6 months (hardware, config, testing)Days to weeks
Expertise RequiredSenior network engineers on staffZero - we handle everything
Ongoing Ops24/7 NOC, patch management, troubleshootingIncluded in service
Hardware InvestmentCAPEX for edge appliancesOPEX only - no hardware to buy
Multi-vendor ComplexityIntegrating firewalls, SD-WAN, monitoringSingle unified service
ScalingManual provisioning, capacity planningOn-demand bandwidth adjustments
SLA AccountabilityYou own all uptime risk99.99% SLA with Hats Network

Responsibility boundary: Hats Network manages the agreed service; your team retains control of applications and local networks.

Delivery Models

Managed routed connectivity for enterprises who want us to handle the core routing infrastructure while they focus on their applications.

What You Get:

  • Software-defined routing with traffic segmentation
  • BGP peering at your edge (optional)
  • Complete traffic isolation between environments
  • Automatic failover and path optimization
  • Predictable latency across our private backbone

Best For:

  • Multi-office WAN with centralized internet breakout
  • Cloud on-ramp integration (AWS, Azure, GCP)
  • Segmented environments (production, development, voice, security zones)
  • Enterprises without deep networking expertise in-house

Architecture

Hats EPN CoreHong Kong EdgeHong Kong LANTokyo EdgeTokyo LANSingapore EdgeSingapore LANCloud On-RampAWS Direct ConnectAzure ExpressRouteGCP Cloud Interconnect

Simple connection model: We manage the complex backbone. You get a clean handoff at each site.

Use Cases

Multi-Site Enterprise WAN

Connect offices, factories and data centers over a managed backbone. Site handoffs, routing and support responsibilities are agreed during design.

  • Manufacturing: Connect global production facilities to ERP systems
  • Retail: Link stores to centralized POS and inventory systems
  • Professional Services: Reliable video conferencing between offices

Cloud Access

Cloud connections can join the private network. Latency still depends on the cloud region, physical distance and application architecture.

  • AWS Direct Connect integration
  • Azure ExpressRoute connectivity
  • Multi-cloud architectures with consistent performance

Critical Workloads

For voice and other delay-sensitive traffic, agree latency, jitter and packet-loss requirements before provisioning.

  • Financial Trading: Sub-50ms latency between trading venues
  • Healthcare: Reliable DICOM image transfers for telemedicine
  • Real-time Collaboration: Consistent video and voice quality

Benchmarks for Critical Workloads

TU-T guidance commonly uses <150ms one-way delay for highly interactive voice tasks.

Microsoft’s Teams connectivity test passes with UDP latency <100ms, UDP jitter <30ms, and UDP packet loss <1%.

Sources: ITU-T Rec. G.114 (05/2003), Microsoft 365 network connectivity test tool

Service Specifications

SpecificationRoutedSwitchedUnderlay
Handoff TypeBGP or Static802.1Q VLANIP or BGP
Routing ControlHats-managedYou manageMinimal
MTU1500 or 9000 (Jumbo)1500 or 90001500 or 9000
MulticastAvailableTransparentNo
IPv6NativeNativeNative
SLA99.99% uptime99.99% uptime99.99% uptime

Traffic Segmentation & QoS

Traffic classes can be configured for the following workloads:

Traffic ClassPriorityTreatmentTypical Use
Real-TimeHighestGuaranteed bandwidthVoice, video conferencing
CriticalHighLow latency queueTrading systems, ERP
BusinessStandardStandard forwardingEmail, SaaS applications
DefaultBest effortStandard forwardingBulk transfers, backups

No VRF configuration needed - traffic segmentation is handled by our platform based on your requirements.

FAQ

What's the difference between Routed and Switched Private Network?

Routed Private Network: We manage the routing. You connect your edge device to our network, and we handle all the complexity of path selection, traffic segmentation, and optimization. Best for organizations that want "it just works."

Switched Private Network: We provide transparent Ethernet transport between your sites. Your routers see each other as directly connected on the same LAN segment. You manage all IP addressing and routing. Best for organizations with existing networking teams who want control.

Use Routed handoff when Hats Network should manage inter-site routing. Use Switched handoff when the design requires Layer 2 adjacency or customer-managed routing protocols.

Can I use Hats EPN as an SD-WAN underlay?

The SD-WAN Underlay option supplies IP transport beneath your existing overlay. The SD-WAN controller remains responsible for overlay policy and path selection.

Underlay capabilities:

  • Consistent baselines: Your SD-WAN makes better path decisions with stable metrics
  • Reduced tunnel flapping: No internet jitter causing unnecessary failover events
  • Guaranteed bandwidth: Private backbone capacity independent of internet congestion
  • Simplified ops: We maintain the underlay; you focus on overlay policies

Supported deployments include VeloCloud, Fortinet, Palo Alto, Cisco and open-source SD-WAN. Confirm the selected platform and handoff during design.

How does traffic segmentation work?

EPN separates traffic into logical domains on shared physical infrastructure. The segmentation policy specifies which domains may communicate.

Common traffic segments:

  • Environment Isolation: Production, staging, and development as separate virtual networks
  • Traffic Type Separation: Voice traffic on its own segment with priority treatment
  • Security Zones: Guest networks, corporate data, and PCI-compliant traffic fully isolated
  • Departmental Segments: Different business units with controlled interconnectivity

Your team defines the segments and access policy; we configure the agreed network boundaries.

What does 'fully managed' actually mean?

Hats Network manages these service components:

We Handle:

  • Core network design and operation
  • Routing protocol management and optimization
  • 24/7 monitoring and incident response
  • Capacity planning and scaling
  • Software updates and security patches
  • Peering and upstream relationships

You Handle:

  • Your edge devices (routers, firewalls)
  • Your internal LAN
  • Your application configuration

Each site receives an agreed handoff. The service order defines the boundary between our managed network and your local equipment.

What are the latency commitments?

We record baseline latency during onboarding. The following inter-PoP figures are reference values, not a site-specific service commitment:

Published Backbone RTT

For the full auto-updated RTT matrix across our PoPs (Backbone measurements), see: Backbone Latency Matrix

RouteLatency
Hong Kong ↔ Tokyo35-45ms
Hong Kong ↔ Singapore35-45ms
Tokyo ↔ Los Angeles90-110ms
Frankfurt ↔ Amsterdam5-8ms

The EPN SLA includes latency variation and packet loss as well as availability. The applicable targets and measurement boundaries are set out in the contract.

Can we connect to cloud providers?

Cloud connectivity options include:

  • AWS: Direct Connect via our partner locations
  • Microsoft Azure: ExpressRoute connectivity
  • Google Cloud: Dedicated Interconnect
  • Alibaba Cloud: Express Connect

Cloud resources can join the same private segments as your sites. Routing and access rules determine which resources are reachable.

How quickly can we get started?

Deployment stages:

PhaseTimelineDetails
Discovery1-2 daysRequirements, topology design
Contracting3-5 daysService order, terms
Provisioning5-15 daysCircuit activation, cross-connects
Testing1-2 daysValidation, acceptance
Go-Live-Production traffic

Typical total: 2-4 weeks from signature to production, subject to site readiness and the agreed design.

Existing customers may be able to reuse installed infrastructure. We confirm the delivery schedule after checking capacity and the required changes.

Getting Started

Tell us about your sites, bandwidth needs, and any cloud connectivity requirements. We'll design a topology that fits.

We provide a detailed proposal including topology, SLAs, and pricing. No surprises.

We handle circuit coordination, equipment installation, and configuration. You provide the cross-connect details.

We validate end-to-end connectivity, establish baseline performance metrics, and hand over operational documentation.

Ready to simplify your WAN?

Send the proposed design to [email protected].

Please include:

  • Number of sites and locations
  • Bandwidth requirements per site
  • Preferred delivery model (Routed/Switched/Underlay)
  • Cloud connectivity needs
  • Target deployment regions

Ready to Crank It Up?

Contact [email protected] with your locations, bandwidth and target destinations.

On this page