Digital globe with red network connections

SD-WAN

Connect branches through an application-aware WAN architecture.

Overview

SD-WAN design starts with application traffic rather than circuit counts. Branch-to-data-centre, internet and cloud flows are assessed against security, latency and continuity requirements. The assessment establishes the roles of existing MPLS and internet circuits, central versus local breakout and operational ownership. The reference drawing explains connectivity; it does not establish a switchover-time or application-performance commitment.

Separate management, control and data paths

Cisco Catalyst SD-WAN Manager handles management, Controller handles control, and Validator assists initial connection orchestration. WAN Edges carry traffic at branches or data centres. These roles should not be interpreted as interchangeable physical links. Administrative access, certificates, DNS and time synchronisation must be checked alongside transport connectivity. Select devices and software against existing licences and supported version compatibility.

CISCO · Figure 10

Cisco SD-WAN: published example topology

Zoom in to explore the roles and connections in the source figure.

Private Cloud · Site 101Control components · Site 1IaaS CloudSite 102DC hostsData-center servers are grouped in one rack in the source.DC switchSwitch connecting the data-center server group to two WAN Edge routers.WAN Edge10.101.0.1First WAN Edge at Site 101; biz-internet and mpls transports match the source.WAN Edge10.101.0.2Second WAN Edge at Site 101; no absent intra-site IPsec tunnel is added.ManagerManagement component shown within Site 1.Controller AOne of the two SD-WAN Controllers shown in the source.Controller BSecond SD-WAN Controller shown in the source.ValidatorOnboarding/orchestration role grouped with control components in the source.Endpoint of the first dashed connection within the source's control-component area.Group endpoint for the second data-center WAN Edge control connection in the source.Group endpoint of the Site 102 control connection in the source.biz-internetPublic internet transport in the source. Grey paths represent its IPsec data plane.mplsPrivate MPLS transport in the source; orange paths depict its data plane.IaaS router AFirst router shown between the IaaS area and internet transport.IaaS router BSecond router in the same IaaS area in the source.WAN Edge10.102.0.1Site 102 WAN Edge. Public and private transport connections are preserved.SwitchSwitch between the Site 102 WAN Edge and endpoint in the source.ClientEndpoint shown within Site 102 in the source.SaaS CloudThe source SaaS cloud includes Office 365, Google, Dropbox and Salesforce, with a direct internet-transport connection.Google Cloud · Microsoft AzureAmazon Web ServicesOffice 365 · Google · Dropbox · SalesforceSource System IPs · Site IDs · biz-internet / mpls transport colors
  • IPsec · biz-internet
  • IPsec · mpls
  • Control plane · DTLS / TLS
Explore the diagram

Select a node to read its role. Drag to pan or use the buttons to zoom.

Cisco's Site 101, Site 102 and Site 1 reference figure. System IP values are preserved from the source. Dashed control connections terminate at the component group; individual controller cables absent from the source are not added.

Plan transports and application policy together

Multiple transports do not imply that every application follows the same path. Agree application classes, permitted egress and acceptance criteria with business owners first. BFD measurements and application awareness inform path-selection evaluation; the organisation’s acceptable loss, latency and jitter limits are essential. Include local-breakout security controls and access to central resources in the same policy assessment.

Branch pilot and transport-failure scenarios

Choose a pilot that represents different circuit types and critical applications. Record normal application access and observe session behaviour when a transport fails and returns. Test voice, video, enterprise applications and cloud access separately. Check DNS, security and third-party allow-list dependencies when egress changes. Rollback must preserve existing routing and access for branch operators.

Monitoring, handover and continuous improvement

Operational visibility goes beyond tunnel availability: monitor transport quality, application experience and policy changes together. Establish alarm ownership, diagnostic steps and the evidence to provide to a carrier. Current branch topologies, configuration backups and change records belong in the handover. Discovery establishes suitable products, capacity and service scope; the reference drawing is not a final implementation design.

Technology Partners

All technology partners

Services

  • Consulting and Assessment

    We assess your existing infrastructure and business requirements, recommend suitable technology and support optimization and implementation. Our consultancy covers networks, data centers, unified communications, security and network optimization.

  • Architecture Design

    We plan, implement and commission network, server and security infrastructure. Scope includes data centers, virtualization, storage, backup and disaster recovery, with handover and ongoing management where agreed.

  • Deployment and Integration

    We address network, system and security deployment from site readiness through controlled transition and operational handover.