Network as a Service (NAAS) - Service Terms
The terms in this section, called the “service terms”, apply to a group of services or a specific service within a group.
1. TELUS Network as a Service
The following service terms apply to all TELUS Network as a Service services.
1.1 General Description
Network as a Service, also refer as NaaS Services, is a group of services offered by TELUS that enables you to send and receive data using the Internet protocol and your communications equipment and systems. These services provide connections to the Internet and private networks. TELUS Network as a Service is described in subsections 1.1 to 1.8. TELUS Managed Internet is the foundational service that is ordered with TELUS Network as a Service and is described under Section 1.9. Next Generation Firewall service is an option that can be ordered with TELUS Network as a Service and is described under Section 2.
1.2 Service Infrastructure
Equipment and Network
From time-to-time we will conduct activities to maintain the performance and reliability of your network connection. We will inform you of scheduled maintenance via e-mail notification based on yours e-mail address provided at time of installation.
We will provide you with a customer interface unit that will deliver Network as a Service to your service location. Should that equipment malfunction, we will replace within one business day where overnight courier is available.
We use standard IP addressing and routing standards to deliver Network as a Service. It is your responsibility to maintain your Local Area Network (LAN) in accordance with these standards to ensure service functionality. You must also provide one public static IP address for the Wide Area Network (WAN) port of the Network as a Service customer interface unit.
If it is determined that either the necessary infrastructure is not available, or you do not agree to pay for unforeseen costs to complete the installation, we may cancel the installation and terminate the NaaS Service at that service location. In such a case only, you will not be required to pay the cancellation charges. We will return any installation fees you may have paid, and we will not be required to provide the NaaS Service at that service location.
When using the NaaS Services, you must comply with our acceptable use policy, published at www.telus.com/aup (“AUP”). We may change the AUP at any time. We will publish the changed AUP at the same site, and you are responsible to review this policy to see any changes. You require Internet access network based connectivity.
Bring Your Own Access
For any service location that is not using Internet access provided by us or one of our National HSIA Partners (NHP), you are responsible for resolving access issues. This access is referred to as “Bring Your Own Access or BYOA”. We remain your first point of contact for a service issue(s). If we determine that the issue is with the access provider, you will need to resolve the issue and notify us immediately upon resolution.
We provide 24x7 support for Network as a Service. TELUS advanced technical support for escalated issues operate from 8am-8pm EST Monday-Friday, excluding statutory holidays.
1.3 Service Performance
Network as a Service includes a Service Availability Threshold. The Service Availability Threshold is the percentage of time in a calendar month that the NaaS Services product should be available for your use on a per service location basis as set in the table below. If the NaaS Service product does not meet the threshold, we will provide you, if you make such a request in accordance with the following, a credit on your bill. Requests for such credits must be made within thirty-one (31) calendar days following the end of the month during which the failure has occurred. Requests must be made in writing to the address you have provided us during implementation of the NaaS Services.
If the NaaS Service fails to meet this Service Availability Threshold, we will calculate site availability and consider whether site availability can be reached by either the primary or backup connection and apply the associated credits. We use our remote monitoring and other systems to measure the actual availability result each month and expresses the result as a percentage. When we measure and calculate the result, we assume each month is 30 days, but we include all periods of unavailability over the calendar month, except for any period of unavailability that is caused or contributed to by:
(a) networks or equipment of another carrier or service provider,
(b) you, your network, or your other services,
(c) an event beyond our’ reasonable control, and
(d) except for any period of unavailability that occurs when we are performing maintenance activities.
(e)The total periods of unavailability over the calendar month, less these exceptions, are called the “Total Outages”.
The credit is a percentage of the monthly fixed charge for the NaaS Service at the affected service location up to a maximum of 80% of that monthly fixed charge.
Although we make reasonable efforts to meet the Service Availability Threshold, if a NaaS Service does not meet a threshold, we will not be in breach of this agreement, and the credit provided is your only remedy for such failure. We will not be obligated to pay any other compensation and will have no other liability to you for any failure to meet a threshold.
Notwithstanding the foregoing, if i) in any month the Service Availability Threshold in all the service locations is less than ninety percent (90%), you may terminate Network as a Service entirely, or ii) if for three (3) consecutive months, we fail to meet its Service Availability Threshold at the same service location, you may terminate Network as a Service at that service location; both without payment of any cancellation charges, provided that notice of cancellation must be given within ten (10) days after the end of that month, and cancellation will be effective on a date you specify in you notice of cancellation, but not more than ninety (90) days after the date of the notice of cancellation.
Service Availability Threshold
This table sets out the “Service Availability Thresholds” and credit calculation for Network as a Service. This Service Availability Threshold is calculated on a per-month and per-site basis. Credits can be claimed by contacting us and any outstanding credits for a month can be claimed for 31-days after the month’s results have been published.
|Service||Measure||Standard||Threshold||Total Outage = Credit Amount|
|Network as a Service||Service Availability||100% 7 days x 24 hours||99.99%||≤ 0 hrs 43 mins = 0% of monthly fixed charge , < 0 hrs:43 mins = 20% of monthly fixed charge, < 15 hrs;6 mins = 40% of monthly fixed charge, < 29 hrs:30 mins = 60% of monthly fixed charge, >43 hrs 54 mins = 80% of monthly fixed charge|
The table below is applicable for those service locations that have the High Availability option.
|Service||Measure||Standard||Threshold||Total Outage = Credit Amount|
|Network as a Service||Service Availability||100% 7 days x 24 hours||99.99%||≤ 0 hrs 4.4 mins = 0% of fixed monthly charge, >0 hrs 4.4 mins-< 0 hrs 43 mins = 20% of fixed monthly charge, > 0 hrs:43 min - < 15 hrs;6 mins = 40% of fixed monthly charge, >15 hrs;6 mins - < 29 hrs:30 mins = 60% of fixed monthly charge, > 29 hrs:30 mins = 80% of fixed monthly charge|
1.4 Trial Period
If applicable, prior to the commencement of the service period set out in Your Services & Summary Charges section, we agree to provide you with Network as a Service for a trial period not to exceed the time period outlined in the “Service Trial Attachment” jointed to this document. The service period for the Network as a Service will then begin upon the successful completion of the trial period as outlined in the Service Trial Attachment, if applicable. If the NaaS Services under trial fails to meet the agreed upon success criteria, you may cancel the Network as a Service without cancellation charges or any penalty. If you are renewing the Network as a Service and the Network as a Service is already installed when you sign this agreement the service period begins from signing without the possibility for the NaaS Services to be under trial.
You are responsible for the security of your network, for implementing your own security policies, and for obtaining any security services to protect your network. We provide a built-in transmission control protocol (TCP) firewall on the Network as a Service customer premise equipment, also known as customer interface unit (“CPE”). You are required to configure the TCP firewall using the Network as a Service portal according to the desired policies. An optional chargeable White Glove configuration service is available to provide a TELUS agent to work with you to configure the desired policies. No guarantees, warranties or service levels are provided regarding the performance of this TCP firewall.
If security services are separately purchased from and provided by us, the service terms associated with that purchase would govern the security services.
A monthly fixed charge applies for each Network as a Service based on selected NaaS Services product and service period. A one-time charge for installation will be billed. In the event you wish that we set up your service configuration, an additional one-time charge will also be billed. All such charges are set out in Your Services & Summary Charges section.
We will start the billing cycle for each service location 30 days after the Network as a Service has been installed in that service location.
After 3 months from the installation of each NaaS Services product, you may request us to upgrade or change Network as a Service product, although your monthly fixed charge may change.
1.8 Service Cancellation Charges
When your Network as a Service is cancelled, we calculate the service cancellation charge using the table below. The service cancellation charge is the aggregate of the percentage of the total monthly charges remaining for the service period after cancellation:
|Month of service period at which the cancellation occurs||% of fixed monthly charges for remaining service period|
|0 – 24 months||100 %|
|25 – 60 months||50 %|
We may, at our sole discretion, waive the cancellation charges if you replace the terminated NaaS Services with a TELUS service where the value of the replacement service is greater than the value of the terminated service(s).
Should the Network as a Service be terminated and the equipment is not returned within 30 days of cancellation, you will be charged for the equipment.
1.9 Managed Internet
These Service Terms and Conditions apply to all TELUS Network as a Service - Managed Internet specified in Your Services & Summary Charges section
NaaS Service - Managed Internet is for customers who rely on the Internet for critical business functions such as access to cloud hosted applications. It provides un-policed connectivity to the public IPv4 Internet and is suitable for any Internet Protocol version 4 (IPv4) application.
The NaaS Service - Managed Internet products available from TELUS are:
|Product||Max Bandwidth (Mbps) Bi-directional|
|NaaS Service - Managed Internet - 25||Up to 25|
|NaaS Service -Managed Internet - 100||Up to 100|
|NaaS Service -Managed Internet - 300||Up to 300|
|NaaS Service -Managed Internet - 500||Up to 500|
The maximum bandwidth provided by each of the above products cannot exceed your Internet access available bandwidth. In the event of a mismatch between the bandwidth of the access and Network as a Service, the actual bandwidth will be the lower of the two.
Your Services & Summary Charges section lists the products you have selected. At any time, you may ask us to change the product, although the monthly fixed charge may change and one-time charges may apply.
The NaaS Service - Managed Internet standard features include:
|Managed Internet Features||Feature Description|
|Proactive Management & Monitoring||Around the clock surveillance, fault management, configuration management|
|LTE Wireless Resiliency with external modems||Used as a backup, TELUS’ LTE (Long Term Evolution) connection will take over if the primary access fails. If there is no TELUS LTE coverage, you will need to order a second physically diverse wireline access for backup. If you are unable to or do not order a second wireline access you will not be able to receive any credits for a failure of the service to achieve the Service Availability Threshold. The LTE Mobility backup provided with TELUS Network as a Service is intended only for providing a backup path for the Network as a Service. Any other use of the LTE mobility backup will result in charges applied back to you, including to but not limited to, the data usage incurred.|
|CPE||A CPE is provided at the service location. The CPE is our property and must be returned when the Agreement ends or is terminated or it will be charged|
|99.9% availability Service Availability Threshold||99.90% Service Availability Threshold is measured monthly with reactive credit if target is not meet. This is further described below – under the Service Availability Threshold section.|
|Proactive Monitoring||We will monitor the Service and where possible proactively correct your network issues. A toll free number is also provided to call in for issues.|
|Online Portal Configuration||A portal is provided to you for configuration and viewing Service Availability Threshold and network performance reports.|
|Next Business Day CPE replacement||If the Network as a Service CPE has failed a replacement will be shipped using next business day shipment if this delivery option is permitted by our courier.|
|Port Address Translation||Network as a Service provides both Network and Port Address Translations to provide hosts behind the network equipment to access the Internet.|
|Flow-based Quality of Experience (QoE)||Traffic can be grouped based on flows and the groups can have priorities assigned to them.|
|Service Level Availability Reporting||The Network as a Service portal will provide up to date reporting on the Service Availability Threshold of each service location in your network.|
|Service Analytics Reporting||Network and service performance reporting is displayed in the Network-as-a-Service portal.|
|Stateful TCP Firewall with Access Control List||Network as a Service provides built-in stateful TCP firewall protection|
White Glove Installation
We must install NaaS Service - Managed Internet at each of your service location to cable, power up and activate the equipment and LTE modem according to our standards. We will also configure all WAN facing policies including WAN ports, Access Control List (ACL), Flow-based Quality of Experience (QoE) and resiliency options.
The Managed Internet service optional features include (charges also listed in the Summary Charges table):
|Optional Features||Feature Description|
|Network as a Service Virtual Private Network with Encryption||Network as a Service offers an optional IPsec encryption between Network as a Service sites to create virtual private networks.|
|On-Site CPE Spare||An on-site spare is available to reduce repair time of failures due to defective Network as a Service CPE. You are responsible for safe storage of the CPE so that in the event of a CPE replacement this CPE can be easily accessible and in working condition.|
|High Availability (99.99% Service Availability Threshold with Dual CPE)||Two CPEs are deployed at a site which are setup in high availability mode. The two CPEs are both active and when one fails, all the traffic will failover to the other CPE. The Service Availability Threshold of a service location with this option is increased to 99.99%.|
|NaaS-MPLS Gateway||The NaaS-MPLS gateway connects a service location to TELUS MPLS Network or to TELUS hosted services in our data center such as TC2. With the gateway traffic can pass between NaaS and TELUS MPLS networks.|
|White Glove Configuration||This feature provides you with 2 hours of professional service time with our back office team working together with your contact to provision and configure the Network as a Service service.|
TELUS Managed NaaS |
If you have service locations in the United Sates one of the following product is mandatory for those service locations.
|Product||Max Bandwidth (Mbps)Bi-directional|
|TELUS Managed NaaS - 25||Up to 25|
|TELUS Managed NaaS - 100||Up to 100|
|TELUS Managed NaaS - 300||Up to 300|
|TELUS Managed NaaS - 500||Up to 500|
TELUS Managed NaaS replaces the NaaS Managed Internet service detailed above when NaaS Services are provided by TELUS Communications (U.S.) Inc. to service locations in United States
|TELUS Managed NaaS||TELUS Managed NaaS provides a Managed virtual private network (VPN) service that connects the service locations in United States to your Canadian service locations.|
The installation of the TELUS provided CPE at US service locations can be performed by one of our field installation partners (under separate agreement directly with such pre-approved third party) or by you with guidance from us
US Service locations will not have a TELUS-provided LTE backup and in order to get the standard 99.9% Service Availability, you must provide two (2) diverse accesses for each NaaS US service location.
On-site CPE spare is also required for all US service locations. If TELUS’ provided CPE fails, you are responsible to swap the TELUS provided CPE with the on-site CPE spare and activate it with our remote guidance. On-site CPE spare is not included in the monthly fixed charge and must be ordered separately from the Naas Service - Managed Internet US
1.10 Managed Next Generation Firewall
These Service Terms and Conditions apply to all TELUS NaaS Service - Managed Next-Generation Firewall (NGFW) specified in Your Services & Summary Charges section.
Firewall provides a managed security offering leveraging Software Defined -- Wide Area Network and virtualized technology to address security concerns and threats. For each Managed NGFW Service as described in Your Services & Summary Charges section, we will provide a managed cloud based Next-Generation Firewall for your use to access the Internet.
The Managed NGFW Service offered throughput options available from TELUS are:
|Product||Total throughput (Mbps) Bi-directional|
Offered throughput is based on total traffic, in both directions, going through the firewall at any time. Site to site communications for your network are using Network as a Service Internet Virtual Private Network (VPN) with encryption features and will not through the Next Generation Firewall. Only traffic destined to the Internet or external networks will be using the Next-Generation Firewall Service. Offered throughput is an estimate only, and not a commitment, as there can be several factors that will influence the final capacity, such as type and number of features enabled, size of the policy table, packet size, number of VPNs, speed of each site access and packet header as examples.
Use of the Managed NGFW Service may require interaction and communication with facilities hosted outside Canada which may result in your data being sent to and hosted on such facilities.
Your Services & Summary Charges section lists the Managed NGFW Service you selected. At any time, you may ask us to change the Managed NGFW Service, although the monthly fixed charge may change and one-time charges may apply.
The following Managed NGFW Service table contains the elements that form the foundation of the Managed NGFW Service along with the allocation of responsibilities between us. Additional service details for each Service Threshold offerings can be found at:
We can change some service elements in order to enhance the provision of the Managed NGFW Service. You will receive a notice of the change.
|Service Element||Description||Customer Responsibility||TELUS Responsibility|
|Software||Includes all of the Managed NGFW Service and pre-defined security policies documented in the Service description, maintenance of Service configuration and ensuring software is at certified version levels supported by TELUS.||No||Yes|
|Software||Confirm pre-defined policies and Managed NGFW Service as documented in Service description does meet your needs and expectations.||Yes||No|
|Software||Provide any additional software, when applicable, included in the Managed NGFW Service such as for example: VPN client, AD agent, etc. Additional charges may apply.||No||Yes|
|Software||Install and maintain endpoints or servers where additional software, when applicable, need to be install.||Yes||No|
|Use of TELUS Systems & Infrastructure||Includes TELUS trouble ticketing system to track and report issues; provide access to TELUS Managed Security Services portal; monitor Service (7x24); provide patch management; portal reporting and monthly SLO performance reports.||No||Yes|
|Scheduled Maintenance & Change Management||Engage us on any new items that may necessitate a change after Managed NGFW Service is accepted when applicable. We will inform you of any applicable charges. Included changes are made Mon-Fri 6am to 6pm EST. Schedule maintenance to install firmware patches and updates; maintain current security signatures as approved by us and maintain configuration documentation accessible to you as requested.||No||Yes|
|Scheduled Maintenance & Change Management||We will inform you of any applicable charges for change request you submit. Included changes are made Mon-Fri 6am to 6pm MST. Schedule maintenance*** to install firmware patches and updates; maintain current security signatures as approved by us and maintain configuration documentation accessible to you as requested.||No||Yes|
|Scheduled Maintenance & Change Management||Ability to schedule change requests to fit your change management process.||Yes||Yes|
|Event Response (Service Assurance)||Provide a designated contact for us to communicate the status of single ticket events and any systemic problems impacting our ability to meet Service Thresholds. Contact would be available for first level trouble shooting and problem diagnosis.||Yes||No|
|Event Response (Service Assurance)||Provide single point of contact to create the trouble ticket and follow through to resolution.||No||Yes|
|Security Management||Notify our single point of contact of your primed changes that may impact the operation of the Security Service(s).||Yes||No|
|Security Management||Includes 24x7 logging of purchased Managed NGFW Service (s). Work with you to ensure proper service operation when notified of your primed changes and ensure devices maintain latest security signatures approved by us.||No||Yes|
One-time Installation Charges
We will provide initial configuration based on the pre-configuration, pre-defined security policies and service configuration implementation as defined in Your Services & Summary Charges section, as a one-time charge. Initial configuration, when applicable, is based on the information you have provided at time of service ordering. If you need additional support to define the security policies to be implemented or to review existing security policies, we can provide additional support through a White Glove security consulting block of 6 hours that can be ordered. Additional charges may apply.
Prevention of Virus Propagation
The Services do not include the installation, configuration and maintenance of anti-virus software, and without limiting anything else in this Agreement, we make no warranties relating to, and is not responsible for, the detection or prevention of viruses or the effect of any viruses on your hardware, software, LAN or facilities, even if the introduction of the viruses is related to the provision of the Services.
Managed NGFW Service provide ITIL (Information Technology Infrastructure Library) based change management process for all configuration changes included in the Service. The following table list includes change request based on the Service subscribed as well as the engagement method based on the change request type:
|Management Tier Option||Standard||Expedited / Non-Standard||Emergency|
|Advanced||Up to 5 changes per month per service||Time and Material||Via Trouble Ticket and Change request|
|Enterprise||Up to 10 changes per month per service||Time and Material||Via Trouble Ticket and Change Request|
The following table outlines the NGFW Change Management Service Level Objectives (SLOs):
|Measure||Indicator||SLO: Business Hours||SLO: After Business Hours|
|Response and completion for Standard Change Request||Elapsed time from reception of your change request to initial acknowledgement of receipt by us.||15 Minutes*||15 Minutes|
|Response and completion for Standard Change Request||Elapsed time notification back by us to completion (unless parties agree that the change shall be made during Scheduled Maintenance).||16 Business Hours||16 Business Hours|
|Response and completion for Standard Change Request||Elapsed time from reception of your change request to initial acknowledgement of receipt by us.||15 Minutes*||15 Minutes|
|Response and completion for Standard Change Request||Elapsed time notification back by us to completion (unless parties agree that the change shall be made during Scheduled Maintenance Window***)||12 Business Hours||12 Business Hours|
|Response and completion for Emergency Change Request**||Elapsed time from reception as a trouble ticket priority of SEV2 by us.||15 Minutes*||15 Minutes|
|Response and completion for Emergency Change Request**||Elapsed time notification back by us to completion (unless parties agree that the change shall be made during Scheduled Maintenance Window***).||2 Hours||2 Hours|
- Acknowledgement of Change Request notification within a calendar month does not exceed an average of 15 minutes.
** Emergency changes are implemented following the incident management process and are implemented with 2 hours and following the pre-qualified assessment. Emergency changes requested through Incident management may have billable time associated to the change if the Emergency is related to a route cause outside of our responsibility or ownership.
*** Scheduled Maintenance will take place between 3:00 A.M. – 5:00 AM EST/EDT on Thursdays and 1:00 A.M. – 4:00 A.M. EST/EDT on Sundays, although we may change these time periods at any time with prior notice to you. These scheduled outage periods are excluded from any availability calculations. We reserve the right to execute emergency changes to ensure service availability without your prior approval.
Although we make reasonable efforts to meet the SLO, if a Service does not meet the SLO, we will not be in breach of this Agreement. We will not be obligated to pay any compensation and will have no other liability to you for any failure to meet the above SLOs.
You can perform certain changes to whitelists and blacklists by using the “Customized content list” feature available on the TELUS Security portal. Changes you perform are outside of the change management process described herein and any impact to the service or data remains your sole responsibility. If we need to intervene in order to fix or troubleshoot a change performed by you, charges may apply. The “Customized content list” feature can be de-activated upon your request.