Uniqcli

What Is SD-WAN? Software-Defined WAN Explained

How software-defined wide-area networking steers branch traffic across broadband, cellular and private circuits — and which parts of a deployment are hardware, licensing and service.

By Uniqcli Team

SD-WAN (software-defined wide-area network) is an approach to connecting branch sites in which a software control layer decides, per application and from central policy, which of several available WAN links each flow should take. An edge appliance at each site terminates whatever transports are available — business broadband, fibre, a private circuit, a cellular connection — presents them to the network as one logical path, and continuously measures each one for loss, latency and jitter so traffic can be moved between them without waiting for a link to fail outright.

The point of the abstraction is that policy stops being a per-router configuration job. Instead of an engineer logging into each branch device to express "voice takes the MPLS circuit, backups take broadband", the intent is defined once in a central controller and pushed to every site. That is what makes SD-WAN a management change as much as a networking one: adding a site becomes shipping an appliance that phones home for its configuration, rather than a scheduled visit by someone who knows the CLI.

How does SD-WAN work?

Three pieces do the work. An edge appliance sits at each branch and terminates the local transports. A controller holds the policy and the topology and distributes both. And an overlay — an encrypted tunnel mesh built across whatever underlying links exist — carries site-to-site traffic independently of who provides those links. Because the overlay is decoupled from the underlay, a site can change internet providers without the application policy changing at all.

On top of that sits the part buyers actually notice: application-aware path selection. The appliance identifies traffic — by application signature, by destination, by DSCP marking or by policy — and matches it to a path whose current measured performance suits it. Voice and video go on the link with the lowest jitter; bulk backup goes on the cheapest one; a SaaS application may break out directly to the internet rather than being hauled back to a datacentre first. When a path degrades, flows move without a human deciding, and some implementations can duplicate or forward-error-correct critical traffic across two paths at once so a lossy link stops being audible on a call.

What does SD-WAN replace?

Historically a branch network meant a private WAN — most often MPLS — with a router at each site, static routing policy, and any internet-bound traffic backhauled to a central firewall before it went out. That design was coherent when applications lived in a datacentre. It became expensive and slow once most of the traffic was headed for cloud services that the backhaul route reached the long way around.

SD-WAN does not necessarily remove the private circuit. The common outcome is hybrid: keep a smaller MPLS or dedicated circuit for the traffic that genuinely needs guaranteed transport, add cheaper broadband and often a cellular backup alongside it, and let policy decide what uses which. The saving comes from carrying bulk and internet-bound traffic on commodity links instead of premium ones, and from local internet breakout removing the backhaul hop for cloud applications. The management saving — one policy instead of hundreds of device configurations — is frequently the larger of the two and the harder one to put on a spreadsheet.

What does an SD-WAN edge appliance actually do?

The appliance is a branch router with more responsibilities. It terminates the local links, builds and maintains the encrypted overlay tunnels, measures every path continuously, classifies traffic, applies the central policy, and reports telemetry back to the controller. Many models also carry local firewalling, and in a growing number of designs the security functions are delivered as a cloud service that the appliance steers traffic into rather than performing itself.

Sizing is driven by throughput with encryption enabled, not by port count, and it is worth checking the vendor's figure with the features you will actually turn on — deep inspection and encryption both cost capacity. Beyond that, the practical questions are physical: how many WAN interfaces the site needs, whether it needs an integrated cellular modem or a separate one, whether it will be wall-mounted in a cupboard or racked, and whether the site needs a second appliance for redundancy. A small branch and a regional office rarely take the same model, so an estate is usually two or three appliance types rather than one.

Which parts of an SD-WAN deployment are hardware, licensing and service?

The hardware is the visible part and usually the smallest line: an appliance per site, sometimes two, plus any cellular modems, antennas, transceivers, mounting and cabling. It is also the part that is easiest to price, which is why it dominates early conversations and misleads early budgets.

The licensing is recurring and is where most of the money sits. Vendors licence SD-WAN by site or by bandwidth tier, in subscription terms, and the tier usually governs which features are available — advanced path remediation, application visibility, integrated security and cloud on-ramps are commonly gated. The controller or orchestrator itself is licensed, whether hosted by the vendor or run by the customer. Support contracts and hardware replacement terms are separate again, and on a distributed estate the replacement service level matters more than it does in a datacentre.

The service half is the one that gets under-scoped: designing the policy and the topology, staging and pre-configuring appliances before they ship, coordinating circuit orders with providers whose lead times drive the whole schedule, running the migration site by site without dropping the sites still on the old design, and then operating it. Some organisations run it themselves; many buy it as a managed service. Uniqcli quotes all three together — appliances, subscriptions and the deployment and lifecycle work — on one document, because splitting them across separate purchase orders is the most reliable way for an SD-WAN programme to lose its schedule.

What should you check before buying SD-WAN?

Start with the circuits, because they are the long pole. Broadband and cellular can be provisioned quickly; a new private circuit to a branch can take months, and the migration plan has to be built around the slowest site rather than the fastest. Inventory what each site actually has today, what it can get, and when — before any appliance model is chosen.

Then check the boundaries. What the SD-WAN vendor does and does not consider security is the most common surprise: some platforms include full firewalling at the edge, some expect a separate firewall, and some assume traffic is steered into a cloud security service that is licensed separately. Confirm which model you are buying and what it implies for the sites that break out locally to the internet. Finally, confirm the licensing term and what happens at renewal — the appliance is capital, the licence is not, and an estate whose subscription lapses does not degrade gracefully.

Key takeaways

  • SD-WAN is a software control layer that steers traffic across several WAN links per application, from policy defined centrally rather than device by device.
  • An edge appliance at each site terminates the available transports, builds an encrypted overlay, measures every path continuously, and applies the central policy.
  • It usually supplements rather than replaces a private circuit: a hybrid of MPLS plus broadband plus cellular, with policy deciding what uses which.
  • Local internet breakout removes the backhaul hop for cloud and SaaS traffic, which is often the most visible performance improvement at a branch.
  • Appliance sizing is driven by encrypted throughput with the features you will actually enable, not by port count.
  • The recurring subscription — licensed per site or per bandwidth tier, with features gated by tier — is normally a larger cost than the hardware.
  • Circuit lead times, not appliance lead times, drive the migration schedule; inventory what every site can get before choosing a model.
  • Security scope varies by platform: some include edge firewalling, some assume a separate firewall, some steer into a separately licensed cloud service.

Shop it at Uniqcli

Frequently asked

Does SD-WAN replace MPLS?
Not usually, and treating it as a straight replacement is where SD-WAN projects disappoint. The common outcome is hybrid: keep a smaller private circuit for traffic that genuinely needs guaranteed transport, add cheaper broadband and often cellular alongside it, and let policy decide what uses which. Some organisations do eliminate MPLS entirely, typically where nearly all traffic has moved to cloud services and no application needs a contracted transport guarantee. The right answer depends on what the applications require, not on the technology.
Is SD-WAN a security product?
Partly, and the boundary varies by platform, which is the single most common surprise in a buying process. The overlay itself is encrypted, so site-to-site traffic is protected in transit. Beyond that, some SD-WAN appliances include full next-generation firewalling at the edge; some expect a separate firewall alongside them; and some are designed to steer internet-bound traffic into a cloud security service that is licensed separately. Because local internet breakout deliberately stops backhauling traffic to a central firewall, confirming which model you are buying matters more than it would in a traditional design.
What does SD-WAN actually cost?
Three lines, and the hardware is the smallest. Appliances are a one-time capital cost per site, sometimes doubled for redundancy, plus any cellular modems, antennas and mounting. The subscription is recurring, licensed per site or per bandwidth tier, and the tier usually governs which features you get — so the same appliance can cost very different amounts to run. The third line is the work: design, staging, circuit coordination, site-by-site migration and ongoing operation, either in-house or as a managed service. Any figure that covers only the first line is not a budget.
How long does an SD-WAN rollout take?
The circuits set the pace. Broadband and cellular can often be provisioned in weeks, but a new private circuit to a branch can take months, and a rollout has to be planned around the slowest site rather than the average one. The appliance side is comparatively quick when devices are staged and pre-configured before shipping, because a branch cutover then becomes a swap rather than an engineering visit. Inventory what every site can actually get, and when, before committing to a schedule.
Do I need an appliance at every site?
At every site that participates in the overlay, yes — the appliance is what terminates the local links, builds the tunnels and enforces the policy. Sizing differs though: a small branch and a regional office rarely take the same model, so most estates settle on two or three appliance types. Sites that need to stay up through a hardware failure take a redundant pair, which is a design decision to make per site rather than across the estate. Cloud and datacentre endpoints are handled by virtual instances of the same software rather than by physical boxes.
What is the difference between SD-WAN and SASE?
SD-WAN is about transport: steering traffic across multiple WAN links from central policy. SASE describes a broader architecture that combines that network steering with security functions — secure web gateway, cloud access controls, zero-trust network access — delivered from the cloud rather than from appliances at each site. In practice many vendors sell SD-WAN as the on-ramp to their SASE platform, so the two frequently arrive as one commercial conversation. If a proposal uses both terms, ask specifically which security functions are included, where they run, and how they are licensed.

About the author

Uniqcli Team

Uniqcli's newsroom, buying guides and glossary are produced by our in-house team — seven procurement and technology professionals who source, screen and integrate IT and security hardware every day, working with two editors. Practitioners draft from live sourcing and integration work; editors review every piece for accuracy and plain language before it publishes.

More about the Uniqcli Team
Ask AI about Uniqcli

What is a PDU?

Speccing hardware for a project?

Send your requirement or a bill of materials — we confirm stock, TAA country of origin and a below-market total. No payment up front.