Article
Cisco Catalyst SD-WAN: Understanding Control and Data Paths
Read management components, WAN Edge roles and MPLS/internet transports together in Cisco’s example topology.

SD-WAN design starts with application traffic rather than circuit counts. Branch-to-data-centre, internet and cloud flows are assessed against security, latency and continuity requirements. The assessment establishes the roles of existing MPLS and internet circuits, central versus local breakout and operational ownership. The reference drawing explains connectivity; it does not establish a switchover-time or application-performance commitment.
Cisco Catalyst SD-WAN Manager handles management, Controller handles control, and Validator assists initial connection orchestration. WAN Edges carry traffic at branches or data centres. These roles should not be interpreted as interchangeable physical links. Administrative access, certificates, DNS and time synchronisation must be checked alongside transport connectivity. Select devices and software against existing licences and supported version compatibility.
Zoom in to explore the roles and connections in the source figure.
Select a node to read its role. Drag to pan or use the buttons to zoom.
Cisco's Site 101, Site 102 and Site 1 reference figure. System IP values are preserved from the source. Dashed control connections terminate at the component group; individual controller cables absent from the source are not added.
Multiple transports do not imply that every application follows the same path. Agree application classes, permitted egress and acceptance criteria with business owners first. BFD measurements and application awareness inform path-selection evaluation; the organisation’s acceptable loss, latency and jitter limits are essential. Include local-breakout security controls and access to central resources in the same policy assessment.
Choose a pilot that represents different circuit types and critical applications. Record normal application access and observe session behaviour when a transport fails and returns. Test voice, video, enterprise applications and cloud access separately. Check DNS, security and third-party allow-list dependencies when egress changes. Rollback must preserve existing routing and access for branch operators.
Operational visibility goes beyond tunnel availability: monitor transport quality, application experience and policy changes together. Establish alarm ownership, diagnostic steps and the evidence to provide to a carrier. Current branch topologies, configuration backups and change records belong in the handover. Discovery establishes suitable products, capacity and service scope; the reference drawing is not a final implementation design.
We assess your existing infrastructure and business requirements, recommend suitable technology and support optimization and implementation. Our consultancy covers networks, data centers, unified communications, security and network optimization.
We plan, implement and commission network, server and security infrastructure. Scope includes data centers, virtualization, storage, backup and disaster recovery, with handover and ongoing management where agreed.
We address network, system and security deployment from site readiness through controlled transition and operational handover.