Business Connectivity & Network Services

Summary

emPOWER Connectivity is blueAPACHE's network pillar: a managed wide area network service that bundles SD-WAN, next-generation firewalls, Secure Access Service Edge and carrier-grade Cisco core routing into one service, delivered over the emPOWER Network, the MPLS private core that blueAPACHE built in 2010 and operates itself. The pillar exists so that carriage, firewalls, cloud interconnect and monitoring have a single accountable owner rather than a carrier, a firewall vendor and a hosting provider each blaming the other. This hub sets out what the pillar covers, its two service lines, how the network is built and reached, what the published 99.99 per cent site uptime figure actually requires, the split between a 7am to 7pm service desk and 24x7 monitoring, and how connectivity ties into the Cloud, Security, Collaboration and Managed Services pillars. It is written for network and infrastructure leads, and for buyers replacing a WAN or carrier contract.

Key facts

Fact Value
Service name emPOWER Connectivity, delivered over the emPOWER Network
Network ownership blueAPACHE-owned and operated MPLS private network, built 2010
Core routing Cisco ASR carrier-grade routers; IPv6 ready
Firewalls Palo Alto Networks virtual firewalls (network); dedicated hosted next-generation firewalls per customer; FortiGate CPE used in the Archers deployment
Core points of presence Pacific (Australia), United States, Europe (London), Asia (Singapore)
Data centre interconnection 165+ data centres
Carrier model Tier 1 carrier-agnostic: globally recognised tier 1 carriers plus specialised regional carriers; no individual carrier named
Published site uptime Minimum 99.99 per cent, conditional on multiple carriers, multiple media, dual CPE and firewalls in high availability, dual carriage at each site
Service desk 7am to 7pm on all business days, by phone, email or client web portal
Monitoring 24x7 priority monitoring with a Network Operations Centre; unified threat protection supported 24x7
Public cloud connections Direct connection to Azure or AWS with a VPN-over-internet secondary path; Azure ExpressRoute; AWS Direct Connect
Internet exchange Traffic transits the Australian Internet Exchange; emPOWER Internet is part of the IX peering network
Voice carriage Microsoft Teams Direct Routing, SIP trunking, hosted PBX, contact centre
Contract schedules Schedule 5 emPOWER Network Services; Schedule 6 emPOWER Voice Carriage Services
ISO/IEC 27001:2022 scope emPOWER Network Services and emPOWER Voice Carriage Services are in scope of certificate 202507-118

What the pillar covers

The origin page describes the pillar as secure, resilient connectivity that keeps users, applications, cloud environments and locations connected, combining network infrastructure, secure access and cloud interconnect under one operating model. Its capability list is: resilient business network and internet connectivity; secure cloud, data centre and site interconnect; SASE; ongoing network monitoring and operational management; visibility across performance and availability; and governance and accountability through one connectivity partner.

The emPOWER Connectivity brochure is more specific about what is inside the service:

Capability What blueAPACHE states
Highly redundant designs Multiple carriers, multiple media (fibre and fixed wireless given as examples), multiple CPE devices and firewalls in high-availability configuration
Business-grade MPLS data services Extends the corporate private network without a VPN; each office becomes another IP address on the network
Quality of Service end to end blueAPACHE works with the customer to define business-critical applications and apply QoS policies; voice and video can be prioritised
Internet scalability and IX peering emPOWER Internet port bandwidth scaled up or down on request; part of the IX peering network for lower latency to major SaaS applications
Public cloud connectivity Direct connection to Azure or AWS plus a secondary VPN-over-internet route
Next-generation firewalls Unified threat protection: intrusion prevention, advanced malware protection, application control, web filtering and antispam, supported 24x7
Australia-based VPN agents Always-on VPN for remote access, configurable with single sign-on and multifactor authentication
Direct connection into emPOWER Cloud Access to the ISO 27001-certified emPOWER Cloud fabric with integrated backup and disaster recovery
Voice carriage Microsoft Teams Direct Routing, SIP trunking, hosted PBX and contact centre solutions

Two architecture options are offered: a hybrid of MPLS and internet SD-WAN, or a hub-and-spoke secure SD-WAN using emPOWER Connectivity appliances, with the SD-WAN hub and hosted SD-WAN firewalls located in multiple data centres on the emPOWER Network. Additional SD-WAN appliances at a site allow local internet breakout to be added and scaled later.

What blueAPACHE proactively manages on the customer's behalf is also stated: monitoring, operating system patching of the CPE and firewalls, configuration documentation, nightly configuration backups, and change management.

Services in this pillar

emPOWER SASE

Secure Access Service Edge that combines network and security controls so users get consistent, protected access to applications wherever they work. The brochure describes SASE as bundled within emPOWER Connectivity alongside SD-WAN and next-generation firewalls, with Australia-based always-on VPN agents, single sign-on and multifactor authentication for remote users. It is the component that extends the same policy and threat protection to staff outside the office as to sites on the private network.

emPOWER Core Network and Data Centre Interconnect

The emPOWER Network itself, offered as the resilient foundation connecting offices, data centres and cloud environments. It is a fully meshed MPLS core on Cisco ASR routing with core points of presence in Australia, the United States, London and Singapore, interconnection into 165+ data centres, ExpressRoute and Direct Connect on-ramps to Azure and AWS, and proactive 24/7 monitoring 365 days a year using blueAPACHE's own monitoring console, to which customers are also given access. This is the service under Schedule 5.

How it is delivered

Design starts with the customer's sites and applications. The brochure describes blueAPACHE working with the customer to define which applications are business-critical so that QoS policies can be applied end to end, and choosing between MPLS, internet SD-WAN or a hybrid per site. The redundancy level is a design decision per site: single carrier and single CPE, or the dual-carrier, dual-firewall, dual-carriage configuration that the published uptime figure depends on.

Deployment is staged where the estate is large or international. The Sealy of Australia case study describes six Australian sites first, then one in New Zealand, one in the United Kingdom and ten across Asia-Pacific, with legacy links kept live so voice and data could revert to the old network at any point; the 18-site network went fully live in April 2022, roughly twelve months after the engagement began. The Archers case study describes site links upgraded from 20/20Mbps to 400/400Mbps fibre with FortiGate CPE at each Queensland office connected to a hosted FortiGate high-availability firewall hub in emPOWER Cloud.

Once live, blueAPACHE manages the CPE and firewalls: monitoring, OS patching, configuration documentation, nightly configuration backups and change management. Customers are given access to the same network monitoring and management tools blueAPACHE uses. Moves, adds and changes, including scaling internet port bandwidth, are requested through the standard change process and any additional fees are notified at the time. Scheduled maintenance is carried out within the windows in the Schedule or with at least 3 Business Days' notice.

Network Services under Schedule 5 follow the standard commercial model: a default 36-month Minimum Service Period, fixed fees billed monthly in advance, usage-based fees monthly in arrears, monthly reporting within 5 Business Days of month end, and 6-monthly service reviews. Where third-party carriage costs change, clause 12.5 allows blueAPACHE to vary fees by the same proportion from the date the carrier changed its charges.

Support and service levels

Published availability. The emPOWER Connectivity brochure states that the service "ensures a minimum 99.99 per cent uptime". That figure is tied in the brochure to a specific redundant design: multiple carriers, multiple media, multiple CPE devices and firewalls in high-availability configuration, redundant transmission paths between points of presence, and dual firewalls and dual carriage at each site. The brochure publishes no figure for single-carrier or single-CPE sites. It is a published service level; the contractual Service Level for a site is whatever is written under the heading "Service Level" in the Schedule 5 Service Description, measured with blueAPACHE's tools and subject to the Reasonable Excuse exclusions, which include outages caused by third parties and by third-party software.

Support hours, stated precisely. These two figures are different and are easy to conflate:

Function Availability
Service desk (phone, email, client web portal) 7am until 7pm on all business days
Priority network monitoring and NOC 24x7
Unified threat protection support 24x7

The General Terms and Conditions define Business Hours as 0700 to 1900 AEST/AEDT on Business Days, consistent with the service desk window. emPOWER Managed Services separately advertises unlimited 24/7 help desk support. A customer holding both services should confirm on the Service Order which desk handles network incidents outside 7am to 7pm.

What is not published. No response or resolution targets, no service credit regime, and no packet loss, latency or jitter commitments appear in the brochure or the General Terms and Conditions. The brochure also carries an absolute statement that it is not possible for outside attackers to intrude into a properly secured MPLS core; that is blueAPACHE's positioning language and is not repeated here as an assurance.

How it integrates with the other pillars

Evidence

Customer What was delivered Stated outcome
Sealy of Australia (live April 2022) International voice and data network designed and deployed in stages across 18 sites in Australia, New Zealand, the UK and Asia-Pacific, with ongoing management No disruption to business activity during migration; supports made-to-order manufacturing with a three-day lead time and real-time factory-to-head-office data
Honan Insurance (c. 2020-2021) Palo Alto network remediation during the tender, then whole-of-WAN transformation including international sites, Wi-Fi support and new Sydney data links Regular outages resolved; telecommunications bill reduced by around 65 per cent; office move completed on schedule when the incumbent could not deliver links
Archers The Strata Professionals (2026) Private MPLS WAN, FortiGate CPE at each office, hosted FortiGate high-availability firewall hub with unified threat protection, FortiClient EMS VPN Site links upgraded from 20/20Mbps to 400/400Mbps fibre; shared firewall replaced with dedicated firewall; web filtering and intrusion prevention added
Brotherhood of St. Laurence (from late 2015) WAN evaluated and upgraded across call centres, offices, care facilities and social enterprises; further links, LAN and security for 17 new NDIS sites Upgrade completed in 12 weeks with immediate performance impact; network operated with consistent reliability for the first time

The origin page itself lists Honan Insurance as the related case study for this pillar.

Defining the network boundary

Establish responsibility site by site: customer premises, access circuits, the managed network, cloud interconnects and destination services. The published availability figure depends on the specified redundant design; it should not be applied to a single-link site. Record who owns each circuit and device, how an upstream fault is escalated and which support window applies. Monitoring coverage, fault response and restoration are separate questions that need answers for the actual network.

Which document defines the commitment

The published General Terms v3.6 give the Service Order precedence over the General Terms, followed by the Schedules and then the Acceptable Use Policy (clause 2.3). Record the agreed scope, exclusions and negotiated departures in that document set. A brochure or a procurement discussion does not, by itself, define the customer-specific commitment. Keep the versions supplied at signing with the executed order and signed variations. Two offers with the same service name can cover different systems, operating hours or responsibilities.

Responsibility across the delivery chain

The published terms allow blueAPACHE to subcontract all or part of the Service Agreement without customer consent or a notification requirement. Clause 27.5 nevertheless makes blueAPACHE liable for its subcontractors’ acts and omissions to the same extent as for its employees. This differs from a third-party supplier contracted directly by the customer. Identify which arrangement applies to each dependency in the design. Where supplier identity, delivery location or change notification matters, request a documented supplier list and put any agreed notification or approval requirement in the Service Order; the general clause does not supply that visibility automatically.

Continuity when an external event interrupts service

Clause 23 addresses force majeure separately from normal incident management. Performance is suspended to the extent a qualifying event causes delay or failure. The definition includes specified events outside reasonable control; it is not a blanket classification of every outage. If the delay exceeds 20 Business Days, the other party may terminate by written notice. The clause also requires payment for services to termination and the applicable Early Termination Payment. A continuity plan should cover operational recovery and the commercial consequences of prolonged interruption. Confirm the Schedule’s exit calculation rather than assuming an externally caused outage creates a cost-free exit.

Escalating a contractual dispute

A support escalation and a formal contractual dispute are different processes. Clause 26 begins with a Dispute Notice giving adequate particulars. Representatives meet within three Business Days; unresolved matters then move through the clause’s senior-representative referral and meeting stages before court proceedings. Urgent equitable relief and disputes over whether the agreement was validly terminated are exceptions. Keep incident records, service measurements, approvals and correspondence together so the disputed obligation and requested outcome can be identified. Raising a ticket does not necessarily satisfy a formal notice requirement; use the agreement’s notice process for contractual disputes.

Customer content and take-down requests

Clause 14 distinguishes operating the service from responsibility for the customer’s content. It requires the customer to notify blueAPACHE promptly of relevant take-down notices or directions and comply with them. The terms also reserve rights for blueAPACHE to restrict or remove Customer Data in specified circumstances, including suspected agreement breaches or exposure to harm or liability. These rights are separate from routine availability commitments. Agree who receives regulatory notices and who can authorise operational action, and retain the notice and decision record. The full clause, including its discretion and good-faith wording, is explained in the terms guide.

Sources and scope

The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on service agreement formation and document precedence; subcontracting and assignment; force majeure; dispute resolution; take down notices and customer data. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.

Related

Frequently asked questions

Does blueAPACHE own the network or resell a carrier's?

blueAPACHE owns and operates the emPOWER Network, an MPLS private core built on Cisco ASR routers that it constructed in 2010. Carriage into that core is bought from a mix of tier 1 and specialised regional carriers on a carrier-agnostic basis; no individual carrier is named in blueAPACHE's published material. The service the customer contracts for is with blueAPACHE, which manages the CPE, firewalls and monitoring.

Does the 99.99 per cent uptime apply to every site?

No. The brochure ties the minimum 99.99 per cent figure to a site design with multiple carriers, multiple media such as fibre and fixed wireless, multiple CPE devices and firewalls in high-availability configuration, and dual firewalls and dual carriage at each site. A single-carrier or single-CPE site is not covered by that published figure. The enforceable Service Level for each site is the one in the Schedule 5 Service Description.

What are the support hours for connectivity?

The service desk is available from 7am until 7pm on all business days by phone, email or the client web portal. Priority network monitoring, the Network Operations Centre and unified threat protection support run 24x7. If your organisation also holds emPOWER Managed Services, which advertises unlimited 24/7 help desk access, confirm on the Service Order which desk handles after-hours network incidents.

Where are the network's points of presence?

Core points of presence are in Australia (Pacific), the United States, London (Europe) and Singapore (Asia), with interconnection into more than 165 data centres. Network traffic transits the Australian Internet Exchange, and emPOWER Internet is part of the IX peering network, which blueAPACHE states lowers latency to major SaaS applications such as Microsoft 365, Teams, Zoom and Salesforce.

Can emPOWER Connectivity connect us directly to Azure or AWS?

Yes. The brochure lists direct connection to Azure or AWS with a secondary VPN-over-internet route for redundancy, and the emPOWER Network provides ExpressRoute connections for Azure, SharePoint and Microsoft 365 and a Direct Connect link to AWS. Direct connection into emPOWER Cloud is also included.

Is SASE included in emPOWER Connectivity or sold separately?

The emPOWER Connectivity brochure describes SASE as bundled with SD-WAN, next-generation firewalls and Cisco core networking in a single managed connectivity solution, with Australia-based always-on VPN agents supporting single sign-on and multifactor authentication. emPOWER SASE also has its own service page. Whether it is priced inside a given connectivity order or as a separate line is set on the Service Order.

What security is built into the network?

Unified threat protection on dedicated hosted next-generation firewalls: intrusion prevention, advanced malware protection, application control, web filtering and antispam, supported 24x7. At the core, blueAPACHE runs Palo Alto Networks virtual firewalls and states its network security approach covers identity and access management, intrusion detection and mitigation, application-level monitoring, perimeter protection and secure VPN provisioning. blueAPACHE states it is ISO 27001 certified and operates at ASD Essential 8 Maturity Level 3.

What does blueAPACHE manage on our behalf?

For the CPE and firewalls that make up emPOWER Connectivity, blueAPACHE states it manages monitoring, operating system patch updates, configuration documentation, nightly configuration backups and change management. Customers are given access to the same network monitoring tools blueAPACHE uses.

Can we use the network for voice?

Yes. Voice carriage is part of the pillar: Microsoft Teams Direct Routing and PSTN services, SIP trunking and terminations, hosted PBX and contact centre solutions. Quality of Service policies can prioritise voice and video end to end. Voice carriage is contracted under Schedule 6 and is within blueAPACHE's ISO/IEC 27001:2022 certified scope.

How long is a connectivity contract?

Network services follow the default 36-month Minimum Service Period unless the Service Order states otherwise, renewing in 36-month periods. If a third-party carrier changes its charges to blueAPACHE, clause 12.5 of the General Terms and Conditions allows blueAPACHE to vary the fees by the same proportion from that date. Early exit triggers an Early Termination Payment calculated under Schedule 5.

Source

Origin page: https://www.blueapache.com/empower-services/connectivity/

Knowledge Base

What is emPOWER Connectivity?

emPOWER Connectivity is blueAPACHE's managed wide area network (WAN) service that delivers secure, resilient connectivity keeping users, applications, cloud environments and locations connected with consistent performance, visibility and control.

What core networking technologies does emPOWER Connectivity bundle together?

emPOWER Connectivity bundles Software-Defined WAN (SD-WAN) for flexible network management, Next-Generation Firewalls (NGFW) for advanced security, Secure Access Service Edge (SASE) for secure connectivity, and Cisco carrier-grade core networking for robust infrastructure, all in a single managed solution.

What network is emPOWER Connectivity delivered over, and what does it connect to?

emPOWER Connectivity is delivered over the emPOWER Network, blueAPACHE's own MPLS private core network, and connects directly to the emPOWER Cloud fabric for integrated cloud infrastructure and disaster recovery services.

What uptime guarantee does emPOWER Connectivity offer?

emPOWER Connectivity guarantees a minimum 99.99% uptime, but only under specific redundant site designs requiring multiple carriers, multiple media (such as fiber and fixed wireless), multiple CPE devices and firewalls in high-availability configuration, and dual firewalls with dual carriage at each site. This figure does not apply uniformly to all connectivity designs.

What support and monitoring is available for emPOWER Connectivity?

The service desk (phone, email, client portal) is available from 7:00 AM to 7:00 PM on business days, while priority network monitoring, the Network Operations Centre (NOC), and unified threat protection support are all available 24x7.

Does emPOWER Connectivity require a VPN to extend corporate private networks?

No, emPOWER Connectivity includes business-grade MPLS data services that extend corporate private networks without requiring a VPN.

What role does Quality of Service (QoS) play in emPOWER Connectivity?

Quality of Service (QoS) management is included in emPOWER Connectivity to prioritize business-critical traffic across the network.

In which country does blueAPACHE provide emPOWER Connectivity services?

blueAPACHE provides emPOWER Connectivity services in Australia.

Images on This Page