Skip to content
Article

What Is SD-WAN? What It Does and How It Differs From MPLS

SD-WAN connects branches over several links and manages traffic centrally. We explain how it differs from MPLS, its benefits and limits, and SASE.

Oğuzhan Gerçek··8 min read
What Is SD-WAN? What It Does and How It Differs From MPLS

Short answer: SD-WAN (software-defined WAN) is a networking approach that connects branches, the data center and the cloud over different links such as MPLS, internet and 4G/5G, and manages those links with central software. It builds an overlay of tunnels on top of the links, continuously measures each link's latency and packet loss, and sends each application over the most suitable link at that moment. Unlike MPLS, it is not tied to a single operator's network, and it can send SaaS traffic straight to the internet from the branch instead of detouring through the data center. Securing that direct internet traffic needs its own design; SASE is the name of the framework that delivers networking and security together.

What is SD-WAN?

A WAN (wide area network) connects an organization's branches in different cities, its data center and its cloud resources. What sets it apart from the local area network (LAN) inside a building is that its connections run over operator links.

The standard definition of SD-WAN comes from MEF, which now operates as the Mplify Alliance. MEF published what it calls the industry's first SD-WAN standard as MEF 70 in 2019; the current version is MEF 70.2, dated October 2023. According to the standard, an SD-WAN service is an overlay service that optimizes the transport of IP packets over one or more other connectivity services; it is aware of application flows and forwards traffic based on those flows and on policies. MEF calls the internet access, IP or Ethernet links underneath "underlay connectivity services".

How SD-WAN differs from traditional WAN and MPLS

The traditional way to connect branches is an MPLS service bought from an operator. In MPLS (RFC 3031), a packet is classified once, as it enters the network, and gets a label; at subsequent hops routers no longer analyze the IP header and forward by label. In enterprise MPLS VPNs (RFC 4364), the operator provides a private IP VPN to the customer over its own IP backbone.

NIST SP 800-215 describes the weakness of MPLS this way: because MPLS is a separate network, internet access is available only through designated and limited access points, which increases latency for time-sensitive corporate applications. As applications move to SaaS and the cloud, that detour becomes more visible.

SD-WAN starts from a different place: it manages the overlay on top of the links rather than the link itself. According to NIST, SD-WAN removes the tight coupling between the control plane and the data plane and can use any WAN transport, such as MPLS, broadband internet, 4G/LTE or 5G. So moving to SD-WAN does not mean giving up MPLS; an MPLS link can stay as one of the links under the overlay.

How does SD-WAN work?

SD-WAN's operation comes down to four things:

  • Central management: Rules are not written device by device in every branch. NIST writes that SD-WAN enables the centralized specification of policies such as access control and routing; according to MEF 70.2, the service typically gives the customer a web portal or API through which it can change policies.
  • Edge device and zero-touch provisioning: Every branch has a physical or virtual SD-WAN edge device. According to Cisco's design guide, a new edge router that is connected to a link and powered on discovers its control components automatically, authenticates to them and downloads its prepared configuration.
  • Overlay: Edge devices connect to each other with tunnels over every underlying link. According to MEF 70.2 the service can offer encryption between edges; in Cisco's architecture, edge routers communicate over IPsec tunnels on each transport.
  • Application-aware path selection: SD-WAN keeps measuring the quality of each link. Cisco's application-aware routing tracks packet loss, latency and jitter on the tunnels; if a path falls below the defined target, it moves the traffic to the best available path. Policy is written per application: video calls take the low-latency link, large file transfers take the cheaper one.

When a link goes down completely, traffic shifts to another one; MEF 70.2 also defines designating a link purely as a backup.

Why does SaaS traffic break out directly from the branch?

According to Cisco's documentation, a branch routes SaaS traffic over the overlay to the data center by default; from there it passes through the security devices and goes out to the internet. Cisco's design guide lists the cost: backhauling traffic to a central site increases bandwidth utilization on the security and network devices, and adds latency that hurts application performance.

The answer is what MEF 70.2 calls "Internet Breakout": application flows selected by policy go straight to the internet over the branch's internet link. Cisco calls this direct internet access (DIA), and its Cloud OnRamp for SaaS feature probes all available links to pick the best path for SaaS applications. We explain how SaaS applications work in an organization in our SaaS article.

The price is security. In Cisco's words, DIA can pose security challenges because remote site traffic needs security against internet threats: traffic that used to pass through the central firewall now goes out to the internet from every branch separately.

Benefits and limits for organizations with branches

Benefits:

  • Several links are used at the same time, and when one drops, traffic moves to another automatically.
  • A new branch can be brought online remotely with zero-touch provisioning.
  • In hybrid organizations that run applications partly in the data center and partly in the cloud, the branch reaches both without a detour.

Limits:

  • SD-WAN picks the most suitable of the links it has; it does not add link capacity. If all links degrade at once, the application degrades too.
  • The SD-WAN service and the links underneath can come from different providers, and MEF keeps the two services separate. During an outage, telling whether the problem is in the overlay or in the link is a job in itself.
  • It does not solve LAN problems inside the branch.

SD-WAN security and SASE

Overlay tunnels may be encrypted, but that does not protect traffic that leaves the branch directly for the internet. For a secure SD-WAN, NIST SP 800-215 lists appliances that combine networking and security functions, and secure remote access functions such as VPN combined into SD-WAN.

According to NIST, Gartner coined the term SASE (secure access service edge) in 2019. In NIST's description, SASE is a framework that converges networking and security functions and delivers them at global scale as a cloud service; the minimal security services in most commercial SASE offerings are firewall, secure web gateway, anti-malware, IPS, CASB and DLP. MEF standardized SASE in MEF 117, dated October 2022, and defined it as an overlay service that secures the transport of the subscriber's IP packets as well as forwarding them. We handle the security side in our network security service and SD-WAN migrations in our network and traffic engineering service.

Frequently asked questions

What does SD-WAN mean? Software-defined WAN: a networking approach that connects branches over several links and manages those links with central software.

What is SD-WAN used for? It makes branch connectivity more resilient by using several links together, sends each application over the most suitable link at that moment and can send SaaS traffic straight to the internet from the branch.

What is the difference between SD-WAN and MPLS? MPLS is a connectivity service an operator provides over its own network. SD-WAN is an overlay built on top of different links, MPLS included, and managed with central policy; it can use MPLS as one of its links.

What is the difference between SD-WAN and a VPN? A VPN builds an encrypted tunnel between two points. SD-WAN also uses tunnels, but adds central management, the combined use of several links and application-aware path selection.

What is SASE? A framework that brings networking and security functions together and delivers them as a cloud service. Gartner coined the term in 2019.

Sources