The problem SD-WAN solves
A business with several branches has to connect them. Historically that meant MPLS — dedicated private circuits from a telecom provider. MPLS is reliable and predictable, but expensive, slow to provision, and awkward now that most applications live in the cloud rather than in a head-office data centre.
With MPLS, a branch user reaching a cloud application often has traffic hauled back to head office and out again — the "trombone" effect — adding latency for no benefit.
How SD-WAN works
An SD-WAN appliance at each site connects to two or more links: broadband, a second ISP, 4G/5G, sometimes MPLS. It then:
- Identifies applications — recognising voice traffic, ERP, video conferencing or general browsing.
- Measures link quality continuously — latency, jitter and packet loss on each path.
- Applies policy — for example, voice always takes the lowest-jitter link; backups take the cheapest link; ERP fails over instantly if a link degrades.
- Encrypts traffic between sites, so ordinary internet links carry business traffic securely.
- Is managed centrally, so policy is defined once and pushed to every site.
The key advantage over simple failover: SD-WAN reacts to degradation, not just outright failure. A link that is technically up but suffering packet loss will be avoided for sensitive traffic.
SD-WAN vs MPLS
| MPLS | SD-WAN | |
|---|---|---|
| Cost | High per Mbps | Substantially lower using broadband |
| Provisioning | Weeks to months | Days, once links exist |
| Cloud traffic | Often backhauled inefficiently | Can break out locally |
| Resilience | Single circuit unless duplicated | Multiple links used actively |
| Encryption | Private, typically unencrypted | Encrypted by design |
| Predictability | Contractual SLA | Depends on underlying internet quality |
Our SD-WAN vs MPLS comparison covers the cost and resilience trade-offs in more depth.
The security dimension
When SD-WAN makes sense
- You operate three or more sites and connectivity costs are climbing.
- Your applications are increasingly cloud-based, making backhaul wasteful.
- You need resilience — a single link outage should not stop a branch working.
- You are opening sites and need connectivity quickly.
- You want central policy control instead of configuring each site individually.
It makes less sense for a single-site business, or where a regulator mandates private circuits.
The bottom line
SD-WAN uses software intelligence to make ordinary internet links behave like a reliable private network — cheaper than MPLS, faster to deploy, and better suited to cloud applications. Deploy it on a security-capable platform so every branch gets proper inspection, not just fast connectivity.