Hats EPN | SD-WAN as a Service
Hats EPN delivers managed SD-WAN connectivity with traffic segmentation and predictable latency across 16+ PoPs. Multi-site private mesh across 4 continents with 99.99% SLA-backed uptime.
Hats EPN (Enterprise Private Network) provides managed routing or Ethernet transport between customer sites.
Why Managed WAN?
Hats EPN connects multiple sites with separate traffic segments and managed routing. We handle the backbone and agreed edge configuration; your team manages the applications and local networks.
Why Managed WAN?
The comparison below separates the tasks managed by Hats Network from those retained in a customer-operated deployment.
| Aspect | Self-Built SD-WAN | Hats EPN (Managed) |
|---|---|---|
| Setup Time | 3-6 months (hardware, config, testing) | Days to weeks |
| Expertise Required | Senior network engineers on staff | Zero - we handle everything |
| Ongoing Ops | 24/7 NOC, patch management, troubleshooting | Included in service |
| Hardware Investment | CAPEX for edge appliances | OPEX only - no hardware to buy |
| Multi-vendor Complexity | Integrating firewalls, SD-WAN, monitoring | Single unified service |
| Scaling | Manual provisioning, capacity planning | On-demand bandwidth adjustments |
| SLA Accountability | You own all uptime risk | 99.99% SLA with Hats Network |
Responsibility boundary: Hats Network manages the agreed service; your team retains control of applications and local networks.
Delivery Models
Managed routed connectivity for enterprises who want us to handle the core routing infrastructure while they focus on their applications.
What You Get:
- Software-defined routing with traffic segmentation
- BGP peering at your edge (optional)
- Complete traffic isolation between environments
- Automatic failover and path optimization
- Predictable latency across our private backbone
Best For:
- Multi-office WAN with centralized internet breakout
- Cloud on-ramp integration (AWS, Azure, GCP)
- Segmented environments (production, development, voice, security zones)
- Enterprises without deep networking expertise in-house
Architecture
Simple connection model: We manage the complex backbone. You get a clean handoff at each site.
Use Cases
Multi-Site Enterprise WAN
Connect offices, factories and data centers over a managed backbone. Site handoffs, routing and support responsibilities are agreed during design.
- Manufacturing: Connect global production facilities to ERP systems
- Retail: Link stores to centralized POS and inventory systems
- Professional Services: Reliable video conferencing between offices
Cloud Access
Cloud connections can join the private network. Latency still depends on the cloud region, physical distance and application architecture.
- AWS Direct Connect integration
- Azure ExpressRoute connectivity
- Multi-cloud architectures with consistent performance
Critical Workloads
For voice and other delay-sensitive traffic, agree latency, jitter and packet-loss requirements before provisioning.
- Financial Trading: Sub-50ms latency between trading venues
- Healthcare: Reliable DICOM image transfers for telemedicine
- Real-time Collaboration: Consistent video and voice quality
Benchmarks for Critical Workloads
TU-T guidance commonly uses <150ms one-way delay for highly interactive voice tasks.
Microsoft’s Teams connectivity test passes with UDP latency <100ms, UDP jitter <30ms, and UDP packet loss <1%.
Sources: ITU-T Rec. G.114 (05/2003), Microsoft 365 network connectivity test tool
Service Specifications
| Specification | Routed | Switched | Underlay |
|---|---|---|---|
| Handoff Type | BGP or Static | 802.1Q VLAN | IP or BGP |
| Routing Control | Hats-managed | You manage | Minimal |
| MTU | 1500 or 9000 (Jumbo) | 1500 or 9000 | 1500 or 9000 |
| Multicast | Available | Transparent | No |
| IPv6 | Native | Native | Native |
| SLA | 99.99% uptime | 99.99% uptime | 99.99% uptime |
Traffic Segmentation & QoS
Traffic classes can be configured for the following workloads:
| Traffic Class | Priority | Treatment | Typical Use |
|---|---|---|---|
| Real-Time | Highest | Guaranteed bandwidth | Voice, video conferencing |
| Critical | High | Low latency queue | Trading systems, ERP |
| Business | Standard | Standard forwarding | Email, SaaS applications |
| Default | Best effort | Standard forwarding | Bulk transfers, backups |
No VRF configuration needed - traffic segmentation is handled by our platform based on your requirements.
FAQ
What's the difference between Routed and Switched Private Network?
Routed Private Network: We manage the routing. You connect your edge device to our network, and we handle all the complexity of path selection, traffic segmentation, and optimization. Best for organizations that want "it just works."
Switched Private Network: We provide transparent Ethernet transport between your sites. Your routers see each other as directly connected on the same LAN segment. You manage all IP addressing and routing. Best for organizations with existing networking teams who want control.
Use Routed handoff when Hats Network should manage inter-site routing. Use Switched handoff when the design requires Layer 2 adjacency or customer-managed routing protocols.
Can I use Hats EPN as an SD-WAN underlay?
The SD-WAN Underlay option supplies IP transport beneath your existing overlay. The SD-WAN controller remains responsible for overlay policy and path selection.
Underlay capabilities:
- Consistent baselines: Your SD-WAN makes better path decisions with stable metrics
- Reduced tunnel flapping: No internet jitter causing unnecessary failover events
- Guaranteed bandwidth: Private backbone capacity independent of internet congestion
- Simplified ops: We maintain the underlay; you focus on overlay policies
Supported deployments include VeloCloud, Fortinet, Palo Alto, Cisco and open-source SD-WAN. Confirm the selected platform and handoff during design.
How does traffic segmentation work?
EPN separates traffic into logical domains on shared physical infrastructure. The segmentation policy specifies which domains may communicate.
Common traffic segments:
- Environment Isolation: Production, staging, and development as separate virtual networks
- Traffic Type Separation: Voice traffic on its own segment with priority treatment
- Security Zones: Guest networks, corporate data, and PCI-compliant traffic fully isolated
- Departmental Segments: Different business units with controlled interconnectivity
Your team defines the segments and access policy; we configure the agreed network boundaries.
What does 'fully managed' actually mean?
Hats Network manages these service components:
We Handle:
- Core network design and operation
- Routing protocol management and optimization
- 24/7 monitoring and incident response
- Capacity planning and scaling
- Software updates and security patches
- Peering and upstream relationships
You Handle:
- Your edge devices (routers, firewalls)
- Your internal LAN
- Your application configuration
Each site receives an agreed handoff. The service order defines the boundary between our managed network and your local equipment.
What are the latency commitments?
We record baseline latency during onboarding. The following inter-PoP figures are reference values, not a site-specific service commitment:
Published Backbone RTT
For the full auto-updated RTT matrix across our PoPs (Backbone measurements), see: Backbone Latency Matrix
| Route | Latency |
|---|---|
| Hong Kong ↔ Tokyo | 35-45ms |
| Hong Kong ↔ Singapore | 35-45ms |
| Tokyo ↔ Los Angeles | 90-110ms |
| Frankfurt ↔ Amsterdam | 5-8ms |
The EPN SLA includes latency variation and packet loss as well as availability. The applicable targets and measurement boundaries are set out in the contract.
Can we connect to cloud providers?
Cloud connectivity options include:
- AWS: Direct Connect via our partner locations
- Microsoft Azure: ExpressRoute connectivity
- Google Cloud: Dedicated Interconnect
- Alibaba Cloud: Express Connect
Cloud resources can join the same private segments as your sites. Routing and access rules determine which resources are reachable.
How quickly can we get started?
Deployment stages:
| Phase | Timeline | Details |
|---|---|---|
| Discovery | 1-2 days | Requirements, topology design |
| Contracting | 3-5 days | Service order, terms |
| Provisioning | 5-15 days | Circuit activation, cross-connects |
| Testing | 1-2 days | Validation, acceptance |
| Go-Live | - | Production traffic |
Typical total: 2-4 weeks from signature to production, subject to site readiness and the agreed design.
Existing customers may be able to reuse installed infrastructure. We confirm the delivery schedule after checking capacity and the required changes.
Getting Started
Tell us about your sites, bandwidth needs, and any cloud connectivity requirements. We'll design a topology that fits.
We provide a detailed proposal including topology, SLAs, and pricing. No surprises.
We handle circuit coordination, equipment installation, and configuration. You provide the cross-connect details.
We validate end-to-end connectivity, establish baseline performance metrics, and hand over operational documentation.
Ready to simplify your WAN?
Send the proposed design to [email protected].
Please include:
- Number of sites and locations
- Bandwidth requirements per site
- Preferred delivery model (Routed/Switched/Underlay)
- Cloud connectivity needs
- Target deployment regions
Ready to Crank It Up?
Contact [email protected] with your locations, bandwidth and target destinations.
Hats Network Services
Dedicated access, managed private networks and routing profiles from Hats Network. Compare handoffs, commitments and deployment requirements.
Hats BDL | Dedicated Internet Access
Dedicated internet access with committed bandwidth, BGP or Layer 2 handoff, and a 99.99% availability SLA.