Frequently Asked Questions
What does SD-WAN do differently from a traditional WAN?
SD-WAN uses software to intelligently manage and route traffic across multiple types of connections, such as broadband, cellular, and MPLS, automatically choosing the best path for each type of traffic rather than relying on fixed, manually configured routing. A centralized controller defines policies that determine how traffic should be handled, for example, prioritizing video conferencing traffic over a connection with lower latency while routing less time-sensitive traffic over a cheaper, higher-latency connection, and those policies are then automatically applied across all of an organization’s branch locations without needing to manually reconfigure routing at each individual site. This represents a meaningful shift from older WAN architectures, where routing decisions were typically fixed and required manual reconfiguration to change.
Why have businesses moved away from traditional MPLS networks toward SD-WAN?
MPLS, the traditional dedicated-line approach to wide-area networking, offers reliable, consistent performance but at considerably higher cost than standard internet connections, and with much less flexibility, since adding or changing an MPLS connection typically requires working directly with a carrier and can take weeks to provision. SD-WAN is generally more flexible and less expensive, since it can use standard broadband and cellular connections instead of dedicated leased lines, while still applying centralized policies and intelligent prioritization to approximate much of MPLS’s reliability benefit. This combination, lower cost and faster provisioning while still maintaining strong performance for critical applications, has driven a substantial shift among businesses toward SD-WAN, often as a hybrid approach that still retains some MPLS for specific high-priority connections.
How does 5G fit into SD-WAN deployments?
5G is increasingly used as a primary or backup WAN connection within SD-WAN setups, especially for retail locations, pop-up sites, or remote branches where running wired connections is slow, expensive, or simply impractical given a short-term lease. Because 5G connections can typically be activated quickly without waiting for a wired installation, organizations can stand up a fully functional branch location’s network connectivity considerably faster than waiting for a traditional wired internet connection to be installed. SD-WAN’s software-defined approach to traffic management works well with 5G specifically because it can automatically detect if a primary wired connection fails and seamlessly shift traffic to a 5G backup without manual intervention, giving organizations a more resilient connectivity setup.
What role does SD-WAN play in supporting cloud application performance?
Since SD-WAN can dynamically prioritize traffic and intelligently choose the best available connection for a given application, it’s commonly used to ensure cloud applications, which used to route inefficiently through a central corporate data center under older WAN architectures, get a more direct, optimized path to the internet rather than backhauling that traffic unnecessarily. Under older WAN designs, traffic destined for a cloud application might travel from a branch office all the way back to a central data center before being routed out to the internet, adding unnecessary latency. SD-WAN can instead route that cloud-bound traffic directly from the branch location to the internet, improving performance for the growing share of business applications running in the cloud.
How does SD-WAN actually decide which connection to use for a given piece of traffic?
SD-WAN systems typically make routing decisions based on a combination of factors defined in centrally configured policies: the specific application generating the traffic, real-time performance metrics like latency, packet loss, and jitter on each available connection, and the relative cost of different connection types. For example, a policy might specify that video conferencing traffic should always use whichever available connection currently has the lowest latency, even if that connection costs more, while routine email traffic can be routed over whatever connection is cheapest as long as it meets a basic reliability threshold. These decisions happen continuously and automatically, meaning SD-WAN can shift traffic mid-session if a connection’s performance degrades.
What happens if one of an organization’s internet connections fails while using SD-WAN?
One of SD-WAN’s core advantages is automatically detecting connection failures and rerouting traffic to a remaining functional connection without requiring manual intervention from IT staff. If an organization has multiple connections at a given location, for example, a primary fiber connection and a backup cellular connection, SD-WAN continuously monitors the health of each connection and can shift traffic to the backup automatically within seconds of detecting that the primary connection has failed or degraded significantly. This failover capability is one of the more commonly cited practical benefits organizations point to when justifying SD-WAN adoption, since it meaningfully reduces the business impact of an outage at a given location.
Is SD-WAN secure on its own, or does it need additional security layered on top?
SD-WAN itself typically includes basic security features like encryption for traffic moving between locations and some access control capabilities, but it’s generally not considered a complete security solution on its own, particularly for organizations with more complex security requirements or significant direct internet access at many distributed locations. This gap is part of what drove the development of SASE, which specifically combines SD-WAN’s networking capabilities with a more comprehensive set of integrated security functions, including firewall protection and zero-trust access control. Organizations using SD-WAN without a more comprehensive security layer typically need to deploy additional, separate security tools to achieve the same level of protection a fully integrated SASE platform would provide.
What kinds of organizations benefit most from SD-WAN?
Organizations with multiple physical locations, like retail chains, restaurant franchises, and distributed branch offices, tend to benefit most from SD-WAN, since it directly addresses the challenge of managing consistent network performance and policy across many sites without individually configuring expensive, dedicated connections at each one. Organizations with significant cloud application usage also benefit meaningfully, since SD-WAN’s ability to route cloud-bound traffic directly becomes increasingly valuable as more business applications move to the cloud. Organizations needing rapid deployment of new locations, like a fast-growing retail chain opening many new stores, particularly benefit from SD-WAN’s ability to get a new location connected quickly using readily available connections like broadband or cellular.