Service types

The connectivity services we shop for. Use this as a quick reference before chatting with the AI assistant — it can suggest the right shape once you describe your endpoints and constraints.

Layer 1 — dedicated optics

  • Wavelength (DWDM)

    1G400G

    Dedicated optical channel on a DWDM ring. Fixed capacity, deterministic latency, no contention.

  • Dark fiber

    Raw fiber pair you light yourself with your own transponders. Maximum control, highest setup cost.

Layer 2 — Ethernet

  • EPL (Ethernet Private Line)

    10M100G

    Point-to-point Ethernet circuit, no other traffic on the path. Strict CoS, easy to scope.

  • EVPL (Ethernet Virtual Private Line)

    10M100G

    Multipoint Ethernet over a shared backbone with VLAN separation. Cheaper than EPL when you have many sites.

  • Metro Ethernet (ELAN/E-LINE/E-TREE)

    10M10G

    Carrier Ethernet across a metro footprint — typically MEF-certified, with rate-limited port speeds.

Layer 3 — IP / MPLS

  • IP transit

    100M100G

    Internet routing access via a carrier's AS. Commit + burst pricing, BGP-peered.

  • MPLS L3VPN

    10M10G

    Routed any-to-any private WAN with carrier-managed routing. Legacy but still common in renewals.

Access — local loops

  • Dedicated Internet Access (DIA, business fiber)

    100M100G

    Symmetric dedicated fiber to a building, SLA-backed. Standard enterprise primary access in NA + EU.

  • Business cable internet

    100M10G

    Asymmetric DOCSIS-3.1 over coax — cheap and fast-to-install, weak SLA. Common as failover.

  • Data-center internet

    1G100G

    IP transit + cross-connect, delivered inside a colo. Burstable, multi-carrier blend possible.

NaaS — on-demand fabric + cloud onramp

  • NaaS / Virtual Cross-Connect

    50M100G

    On-demand L2/L3 between any two ports on a global fabric (Megaport, Equinix Fabric, PacketFabric, etc.).

  • Cloud onramp (private interconnect)

    50M100G

    Private virtual circuit to AWS Direct Connect / Azure ExpressRoute / GCP Interconnect / OCI FastConnect / IBM Direct Link.

Managed overlay

  • Managed SD-WAN

    Vendor-managed overlay across mixed transports — fiber, cable, 5G, satellite — with policy + zero-touch.

Wireless — 5G / LTE / cellular

  • 5G fixed-wireless business

    100M1G

    5G FWA from T-Mobile / Verizon / AT&T / Bell / Rogers / Telus. Useful as primary in non-fiber locations and as failover.

  • Bonded cellular failover (router + multi-SIM)

    Cradlepoint / Peplink / Inseego routers bonding cellular paths for resilient branch access.

Facility

  • Colocation

    Rack / cage / cabinet space in a third-party data center, with cross-connect access to carriers and clouds.

Voice / UCaaS

  • UCaaS (hosted PBX / cloud voice)

    Cloud-hosted calling, messaging, video, presence — RingCentral, 8x8, Zoom Phone, Webex Calling, Teams Operator Connect, Dialpad. Per-seat pricing.

  • SIP trunking

    Wholesale voice termination/origination + DID inventory for on-prem PBXs or hybrid stacks. Per-channel or per-minute pricing.

  • Toll-free numbers (TFN)

    8XX inbound numbers with per-minute or flat-rate pricing. Origination from Bandwidth, Intelepeer, Twilio, Voxbone, others.

  • E911 / dynamic location

    Compliant 911 routing with location dispatch for VoIP — RAY BAUM's Act + Kari's Law for multi-site orgs. Often bundled with UCaaS.

  • POTS replacement / POTS-in-a-box

    LTE/IP-backed analog line replacement for alarms, elevators, fax, fire panels. Granite POTS-in-a-box, Ooma AirDial, Lumen QCC.

  • Audio + video conferencing

    Standalone meeting / webinar / large-event platforms when UCaaS isn't the right vehicle — Zoom Meetings, Webex Meetings, GoTo, BlueJeans (sunset).

Security / SASE

  • SASE (Secure Access Service Edge)

    Cloud-delivered network + security stack: SD-WAN + SWG + CASB + ZTNA + FWaaS converged. Cato, Zscaler, Palo Alto Prisma, Netskope, Cloudflare One, Versa, Aryaka.

  • SSE (Security Service Edge)

    Security half of SASE without the SD-WAN — SWG + CASB + ZTNA + DLP. Right when the buyer already has a WAN strategy and only needs security.

  • ZTNA (Zero Trust Network Access)

    VPN replacement — per-app identity-aware access without giving users a route to the network. Zscaler ZPA, Palo Alto Prisma Access, Cloudflare Access, Cisco Duo / Secure Connect, Cato.

  • CASB (Cloud Access Security Broker)

    Visibility + control over SaaS app usage — shadow IT discovery, DLP for M365/Salesforce/Box, malware scanning, threat protection. Netskope, Skyhigh, Microsoft Defender for Cloud Apps, Palo Alto.

  • Managed firewall / FWaaS

    Vendor-operated firewalls — on-prem appliances managed by the vendor, or cloud-delivered FWaaS. Fortinet FortiSASE, Palo Alto Prisma SASE, SonicWall MSSP, Check Point Quantum.

  • Managed SOC / MDR

    24x7 security monitoring + response — combines SIEM tooling with human analysts. Arctic Wolf, eSentire, CrowdStrike Falcon Complete, Sophos MDR, Rapid7 MDR, Critical Start, Cybereason.