solution brief how to implement sd wan for your organization
Guide | How to Implement SD-WAN for Your Organization
HOW TO IMPLEMENT SD-WAN FOR YOUR ORGANIZATION A SIMPLE TECHNICAL INTRO
EXECUTIVE SUMMARY
Software-defined WAN (SD-WAN) simplifies the management and operation of a WAN (Wide Area Network) by decoupling or separating the networking hardware from the mechanisms that control the network. In other words, SD-WAN essentially creates a logical overlay on top of physical networks that enables central management or orchestration of the WAN.
Benefits of SD-WAN
- OPEX Savings
- Agility
- Better User Experience
With the ability to manage the network via a software overlay, new networking services can be delivered in a fraction of the time that it would take for an on-site technician to do the same work. SD-WAN application performance is monitored for changes in latency, jitter and packet loss. When performance falls below an optimal level, traffic is dynamically routed to another link, ensuring users and applications are always connected. With multiple links to choose from: MPLS, broadband, and wireless, organizations can build higher-performance WANs using lower-cost and commercially available Internet access.
Overlay
An overlay network provides site-to-site connectivity (e.g. VPN). Options include edge routers, software based white boxes, and a vast array of software-defined WAN (SD-WAN) appliances.
An underlay or breakout network provides a direct site-to-internet connection, and includes transport and circuit types such as Multiprotocol Label Switching (MPLS), broadband internet (e.g. DSL, copper cable and optic fiber), wireless (e.g. 5G) and local Internet service providers (ISPs) and mobile network operators (MNOs).
BUILDING BLOCKS OF SD-WAN
- Underlay
- Network Policy
- Cloud Orchestration
- Security
Automates the provisioning, management, operation and monitoring of the Wide-Area Network (WAN). Organizations define a policy in software for routing apps, mitigating performance problems associated with latency, jitter, or packet loss to give users an optimal experience at the lowest possible operating costs. Ideally, a complete security stack is integrated with networking and delivered either on-prem or as a cloud service.
You can use SD-WAN for:
- Steering Behaviors
- Local Breakout
- VPN Overlay
- Backhaul
THREE TYPES OF SD-WAN STEERING BEHAVIORS
- Local Breakout
To control and select the best path for outbound traffic to cloud applications and the Internet. - VPN Overlay
To control the best VPN path between VPN peers, for routing internal traffic between the organization’s sites. - Backhaul
To route Internet traffic on VPN spoke sites through the Headquarters over a VPN tunnel.
Must-Haves for a Secure SD-WAN Solution
GETTING STARTED WITH SD-WAN
The next pages provide a basic high-level overview of how to deploy SD-WAN in your organization, including:
- Connecting your environment
- Setting up your steering policy
- Monitoring your network connections
SD-WAN DEPLOYMENT
Connect the Overlay to the Cloud Orchestration
SD-WAN deployment begins with connecting your overlay components to your cloud-delivered management services.Configure the Underlay SD-WAN circuits
The next step is mapping your physical network interfaces to a common, logical SD-WAN network topology.Define the Network Policy
Next, define how you want to steer network traffic. Source, destination and service objects shared with security management match on the first packet.