What Is SD-WAN?
SD-WAN is a software-defined approach to managing wide area network connectivity. It abstracts the underlying transport (MPLS, broadband, LTE, 5G) and provides centralized management, intelligent traffic routing, and application-aware policies.
Traditional WAN relied on expensive MPLS circuits with fixed routing. SD-WAN can use multiple, lower-cost transport types simultaneously, routing traffic based on application requirements, link quality, and cost. A video conference call might use the MPLS link for quality; bulk data transfers might use broadband for cost efficiency.
SD-WAN consists of three components: edge devices (CPE at each site), a centralized controller (manages policies and routing), and an orchestration platform (configuration and monitoring). Cloud-delivered SD-WAN (from vendors like Zscaler, Palo Alto, Cisco) adds security functions to the SD-WAN fabric.
Benefits
Cost Reduction
MPLS circuits cost $500–$5,000+ per month per site depending on bandwidth and location. Broadband internet costs $100–$500 per month for equivalent or higher bandwidth. SD-WAN enables organizations to replace MPLS with broadband for most traffic, reducing WAN costs by 40–60%.
Improved Application Performance
Application-aware routing directs traffic based on application requirements and real-time link quality. SaaS applications (Microsoft 365, Salesforce) can be routed directly to the internet from branch offices, bypassing the data center and reducing latency. Latency-sensitive applications (VoIP, video) are routed over the best-quality link.
Simplified Management
Centralized management through a single controller enables consistent policy deployment across all sites. Zero-touch provisioning allows new sites to be brought online without on-site technical expertise. Visibility into application performance across all sites from a single dashboard.
Built-In Redundancy
SD-WAN automatically fails over between transport types when a link degrades or fails. Sub-second failover for active-active configurations. Eliminates the single point of failure of traditional MPLS-only WAN.
Architecture
Hub-and-Spoke vs. Full Mesh
Traditional WAN used hub-and-spoke topology: all branch traffic routed through the data center hub. SD-WAN enables full mesh: branches can communicate directly with each other and with cloud services without hairpinning through the data center. Full mesh reduces latency and data center bandwidth requirements.
Data Center Integration
SD-WAN edge devices at the data center aggregate connectivity from all branch sites. For high-availability, deploy redundant SD-WAN edge devices at the data center with active-active or active-passive configuration. SD-WAN complements (not replaces) dedicated connectivity (Direct Connect, ExpressRoute) for cloud workloads.
Internet Breakout
Local internet breakout at branch offices routes internet-bound traffic directly to the internet rather than backhauling it to the data center. Reduces data center bandwidth requirements and improves performance for cloud and SaaS applications. Requires security controls at the branch (cloud-delivered security or local firewall).
Use Cases
- Branch office connectivity: Replace expensive MPLS with broadband + SD-WAN for branch offices
- Cloud connectivity: Optimize connectivity to AWS, Azure, GCP, and SaaS applications
- Multi-data-center connectivity: Connect multiple data centers with redundant, cost-effective WAN
- Remote work: Extend SD-WAN to home offices and remote workers
- Retail/distributed locations: Standardize connectivity across hundreds or thousands of locations
Vendor Comparison
| Vendor | Platform | Key Strengths |
|---|---|---|
| Cisco | Catalyst SD-WAN (Viptela) | Largest installed base; strong enterprise support; Cisco ecosystem integration |
| VMware | VeloCloud SD-WAN | Strong cloud gateway network; good VMware NSX integration |
| Palo Alto | Prisma SD-WAN | Best SASE integration; strong security; cloud-native architecture |
| Fortinet | FortiSASE / SD-WAN | Best price/performance; integrated security; good for mid-market |
| Zscaler | Zero Trust SD-WAN | Best zero trust integration; cloud-native; strong for cloud-first organizations |
Migration from MPLS
Migrating from MPLS to SD-WAN requires careful planning to avoid service disruption:
- Assessment: Inventory all MPLS circuits, contract terms, and bandwidth requirements
- Pilot: Deploy SD-WAN at 2–3 pilot sites alongside existing MPLS
- Validation: Verify application performance and failover behavior
- Phased rollout: Migrate sites in waves, maintaining MPLS as backup during transition
- MPLS reduction: Reduce MPLS bandwidth as SD-WAN proves reliable; eventually eliminate MPLS at most sites
Maintain MPLS at critical sites (data centers, large offices) as a backup or for latency-sensitive applications. Complete MPLS elimination is not always the goal — a hybrid approach often provides the best balance of cost and reliability.
SD-WAN and SASE
SASE (Secure Access Service Edge) integrates SD-WAN with cloud-delivered security: CASB, SWG (Secure Web Gateway), ZTNA (Zero Trust Network Access), and FWaaS (Firewall as a Service). SASE provides consistent security for all users and locations without backhauling traffic to a central security stack.
For organizations adopting zero trust architecture, SASE provides the network foundation: SD-WAN for connectivity, ZTNA for application access, and cloud-delivered security for threat prevention. Leading SASE vendors: Zscaler, Palo Alto Prisma, Netskope, Cisco Umbrella.