SD-WAN and WAN Resilience
Built around SD-WAN, WAN failover, path resilience, cloud connectivity, branch performance, and high-availability networking.
Built around SD-WAN, WAN failover, path resilience, cloud connectivity, branch performance, and high-availability networking.
Built around WAN edge, cloud security, ZTNA, SWG, CASB, FWaaS, DLP, secure remote access, and policy-driven filtering.
Built around SNMP, topology, observability, flow data, syslog, telemetry, bandwidth, discovery, and performance monitoring.
Built around NGFW, stateful inspection, IDS and IPS, DPI, sandboxing, access control, DLP, and integrated firewall operations.
Built around single-stack security, threat prevention, centralized security management, cloud and on-premises security, and vendor reduction.
Built around security event management, audit-ready reporting, continuous compliance monitoring, and framework-oriented visibility.
Built around WAN monitoring, latency, packet loss, dashboards, alerting, root cause analysis, and predictive maintenance.
Built around VPN models, encrypted tunnels, secure remote workers, MFA, IPsec, TLS, and resilient remote connectivity.
Built around 5G backup, LTE failover, cellular WAN, wireless last-mile connectivity, and data-aware wireless routing.
Built around inbound availability, DNS failover, hosted application continuity, and multi-line service resilience.
A modern hybrid WAN may contain multiple types of connections with different performance characteristics. Application flows should be optimized across the best paths to meet business requirements. Path selection can use real-time WAN metrics such as latency, packet loss, jitter, and bandwidth to steer specific application traffic to specific paths for optimal link and resource utilization, as well as to enable users to navigate the path to the application server in the best possible manner. This allows critical applications to use paths that meet their requirements instead of treating every application and every WAN link the same way.
Specific thresholds and algorithms can be used to optimize path selection for each application. These decisions can be based on latency, packet loss, jitter, bandwidth, and other real-time WAN conditions. A business-critical application can therefore follow a different path from less important traffic. The application session state should also remain persistent if the selected path changes. This is especially important for voice, video, databases, and other real-time applications.
The ability to maintain session integrity, failover, and seamless transition for business-critical activities cannot be overlooked. A database session may need to remain connected, and a VoIP call cannot be dropped simply because the WAN path changes. SD-WAN can preserve the application session while moving traffic to another available path. This allows the network to react to changing WAN conditions without forcing the application to restart.
SD-WAN path decisions can be based on real-time WAN metrics rather than only on whether a circuit is physically up or down. If latency, packet loss, jitter, or available bandwidth no longer meets application requirements, traffic can be moved to another path. This allows the network to react to degraded performance before a complete failure occurs. Critical applications can therefore continue using a better-performing connection.
FatPipe provides the differentiated capability to steer traffic based on a combination of breached thresholds across two or more parameters, e.g., switching traffic only if latency exceeds 50 msec and bandwidth utilization exceeds 60%.
A WAN connection may remain active while experiencing increased latency, packet loss, jitter, or bandwidth limitations. SD-WAN can use real-time path metrics to determine whether that connection still meets the requirements of an application. Traffic can then be moved to another path when configured thresholds are exceeded. This allows the network to react to poor service quality rather than waiting for a complete failure.
Using multiple connections can improve resiliency, but the value is greater when those connections do not depend on the same underlying infrastructure. Enterprises can combine dedicated Internet, broadband, MPLS, wireless, LTE, or satellite connectivity. Different technologies may fail for different reasons. SD-WAN provides the framework for using these diverse connections as part of one coordinated WAN architecture.
MPVPN continuously monitors the available WAN paths and can redirect traffic when a connection fails or no longer meets required conditions. Stateful session failover can help maintain active application sessions instead of forcing users to reconnect. Load balancing can redistribute traffic over the remaining healthy paths. Application policies can also ensure that critical business traffic receives appropriate priority during the reduced-capacity condition.
MPLS had been a key element of enterprise network architecture for almost two decades. However, MPLS has limitations such as limited application-aware routing, limited geographic reach, and long provisioning times. MPLS architectures can also hairpin cloud-destined traffic through a central security gateway before sending it to the cloud. This is not an optimal use of bandwidth. As cloud and video application usage increases, operational costs can also rise significantly. Another problem with MPLS circuits is that they tend to be more expensive than Internet lines.
Applications may be deployed in a data center, remote premise, cloud environment, or disaster-recovery site. SD-WAN policies can be centrally managed and updated when the location of an application changes. Those policy changes can then be propagated across multiple sites from a single management interface. This allows the WAN to adapt as applications move without requiring independent changes at every branch.
Traditional WANs were designed mainly for centralized data-center traffic rather than direct cloud access. This can cause cloud and SaaS applications to experience increased latency, inefficient routing, and degraded user experience. SD-WAN can use cloud breakout and more direct routing toward hosted applications. Multi-line and multi-provider connectivity can also provide alternative paths to cloud resources. This can improve hosted application performance regardless of where the application is located.
Traditional architectures may send cloud-destined traffic through a central security gateway before sending it back toward the Internet or cloud. This consumes private WAN bandwidth and can introduce additional latency. SD-WAN can allow trusted Internet-destined traffic to break out locally while applying appropriate security policies. Sensitive traffic between branches, headquarters, data centers, or cloud environments can still be selectively encrypted.
FatPipe provides pure over-the-top delivery for direct, low-latency connectivity between sites, ensuring VoIP and data traffic takes the fastest path without traversing the hosting provider's network. It requires no cloud gateways or infrastructure modifications, supports multiple MPLS links, and adds no significant bandwidth overhead, while optional WAN Acceleration can further reduce bandwidth consumption.
SD-WAN solutions can work with cloud-based environments including AWS, Azure, Google, IBM, and others. Multi-line and multi-provider connectivity give enterprises multiple paths toward hosted applications. Traffic can be routed according to application requirements and current WAN conditions. This helps improve access to cloud-hosted applications without tying the enterprise to one type of carrier connection.
SD-WAN, Multi-WAN and WAN Resilience FAQ
Traditional routed WAN networks were architected primarily for basic routing decisions and packet forwarding. Their major function was to transmit Layer 3 data packets from point A to point B. They had limited awareness of applications, payload visibility, and end-to-end network path. This led to inefficient and unintelligent traffic handling. SD-WAN entered and transformed to overcome these limitations while improving performance, scalability, security, efficiency, and user experience.
The Data transmission uses traditional routing problems like OSPF, BGP, etc., which have known convergence issues resulting in high failover times for traffic from primary to secondary link and vice versa. SD-WAN uses software-defined networking techniques to manage and control disparate WAN circuits through intelligent WAN Routing. Transport routing decisions can be dynamically adjusted in real time. The underlying transport infrastructure is abstracted, pooled, and assigned to applications based on software-defined policies. Application flows can be optimized across the best paths based on latency, packet loss, jitter, and bandwidth. This makes the WAN more responsive to actual application requirements.
FatPipe SD-WAN uses a unique method of data transmission by bypassing the disadvantages of traditional routing protocols using MPSEC, a proprietary mechanism designed to improve link failover times and to introduce additional security over the line.
SD-WAN allows flexibility in connectivity with support for hybrid WAN connections. A user can add any combination of access into the WAN, including MPLS, dedicated Internet, broadband, 3G/4G/LTE, and satellite wireless connections. Traffic flowing across these links can follow corporate policies for security and access. This gives enterprises the ability to use locally available connectivity rather than depending on one network technology or provider.
No. While some users may be willing to replace an MPLS network in favor of a tunnelled network, this may not be the best option for all organizations. SD-WAN can accommodate a legacy network and ensure the network remains usable during any access migration. Enterprises can combine MPLS with dedicated Internet, broadband, wireless, or other WAN connections. This allows migration to take place according to business, security, and operational requirements.
Customers with branches regionally and nationally may need to bring in any locally available link. SD-WAN can support combinations of MPLS, dedicated Internet, broadband, wireless, LTE, and satellite connectivity. The traffic flowing across these links can still follow corporate policies for security and access. This allows each branch to use the connectivity available at that location without changing the overall enterprise WAN approach.
FatPipe has unique capability to aggregate and load-balance traffic on multiple last-mile technologies using MPSEC to provide fast seamless failover.
Enterprises need to increase network availability, uptimes, and SLAs. SD-WAN deploys multiple features to direct packets over disparate networks using intelligent WAN routing. Multiple WAN connections provide alternate paths when one connection fails or becomes unavailable. They can also be actively used for traffic distribution rather than remaining idle as backup circuits. This improves network uptime, application performance, and the overall user experience. It also allows enterprises to make better use of the connectivity they are already paying for.
FatPipe SD-WAN provides a single tunnel with a single IP framework toward the LAN for disparate WAN links terminating on the device. The available bandwidth of these links can be used as part of an aggregated WAN architecture. This allows multiple types of connectivity, e.g., MPLS, dedicated Internet, broadband, wireless, LTE, and satellite connectivity, to operate together rather than as isolated connections. The enterprise can therefore use available WAN resources more effectively while maintaining a simpler logical network architecture.
SD-WAN provides outbound load balancing across disparate technology lines rather than simply keeping one connection active and another idle. It can maximize data traffic and improve data transmission by using available WAN capacity. Multiple load-balancing algorithms can be used, including per-packet, per-session, per-user, and per-application approaches. This provides better utilization of network investments and allows traffic to be distributed according to business requirements.
FatPipe provides an industry-unique feature of per-session and per-packet load balancing without traffic duplication on lines, enabling faster return on investment to customers buying FatPipe as they can save bandwidth up to 50%.
When a WAN link fails, SD-WAN can direct traffic to the additional available lines. The remaining connections continue to carry traffic according to the configured load-balancing and failover policies. This helps maintain service availability without depending on manual intervention. The purpose is to provide uninterrupted connectivity while making use of all healthy WAN paths. When the failed line becomes available again, it can return to the WAN path pool.
FatPipe has the technically sound capability to provide seamless failover with load-balancing in a simple manner that retains user sessions during failover.
Real-time traffic such as VoIP is highly sensitive to interruptions. SD-WAN technology can fail VoIP traffic over in a sub-second without dropping the call. This prevents a WAN circuit failure from becoming immediately visible to the user as a disconnected voice session. Different vendors may implement this functionality differently. Efficient failover should maintain application continuity without unnecessarily duplicating traffic across multiple lines.
Some implementations send the same VoIP traffic over two lines and use whichever data reaches first. Duplicating VoIP traffic can create unnecessary traffic and inefficient use of bandwidth, especially in offices handling many simultaneous calls. A more efficient design can send traffic over one selected line and fail it to another line when required. This provides resiliency without consuming twice the WAN capacity during normal operation.
For applications such as Oracle and SAP, where an active session may contain an important business transaction, SD-WAN can provide stateful sub-second session failover for data traffic. If a WAN line fails in the middle of the transaction, the traffic can be failed over without forcing the session to drop. This helps prevent interruption or loss of application continuity during a network failure.
Production monitoring and other real-time data may be transmitted continuously between locations. If a WAN line fails while that information is being sent, restarting the complete connection can interrupt the process. Stateful SD-WAN can move the existing data session to another line without dropping it. This allows the transmission to continue while the underlying WAN path changes. The application is therefore protected from a physical circuit failure.
SD-WAN can establish secure tunnels between combinations of statically and dynamically assigned IP addresses. It can sense DHCP IP changes provided by service providers for broadband and 4G connections in real time. Traffic can then begin moving using the new address while maintaining the required connectivity. This allows enterprises to use less expensive connections with rotating or dynamic addresses where appropriate.
Traditional Quality of Service or packet shaping generally looks toward the next hop. In a hybrid WAN, multiple potential connections of different types may be available at the same location. Traditional QoS rules may not react appropriately when one circuit fails and the available bandwidth changes. SD-WAN can combine application priorities with current path conditions. This helps preserve business priorities even during partial WAN outages.
SD-WAN can identify applications and apply policies based on their importance and performance requirements. Instead of queuing packets on a single interface, it can take into account multiple available connections and select an appropriate path. This becomes especially important when a higher-capacity circuit fails and applications need to share a smaller backup connection. Business-critical traffic can continue receiving priority under changing WAN conditions.
Hybrid WANs allow corporations to combine private MPLS links with public broadband connections for reliable WAN connectivity at a reasonable cost. Traffic flowing across broadband must be protected appropriately because the network is now using public infrastructure. SD-WAN can use encryption between branch offices, headquarters, data centers, and cloud environments. This allows public and private connections to operate together while maintaining required security policies.
FatPipe has industry-unique patents for secure connectivity for the combination of private MPLS links with public broadband links, providing a seamless aggregate traffic experience for simple, efficient, dynamic, and adaptable data transmission.
Partner connections, consumer devices, cloud applications, and direct Internet access from branches have increased the number of attack points in enterprise networks. Traditional branch routers alone may not address these security requirements. FatPipe SD-WAN appliances can provide firewalling, encryption, application policies, IDS/IPS, web filtering, and other security functions. This allows network connectivity and security policies to operate together at the WAN edge.
The traditional approach used separate hardware devices for separate functions. These could include routers, firewalls, IPS systems, WAN optimizers, load balancers, SSL VPN concentrators, DNS servers, DHCP servers, antivirus systems, and network management appliances. SD-WAN uses network function virtualization and software-defined functions within a common hardware platform. This substantially reduces the amount of hardware required in the enterprise network architecture.
FatPipe provides many SD-WAN and security features in unified hardware and unified software, which is a compelling proposition for enterprises to reduce the total cost of ownership of network and security assets.
Disparate hardware devices introduce additional configuration, maintenance, cabling, management interfaces, and points of failure. FatPipe SD-WAN can combine several networking and security functions within a single device and management interface. This reduces network complexity and can lower annual maintenance costs associated with multiple hardware platforms. High-availability SD-WAN architectures can also reduce the impact of individual device failures.
Depending on the deployment, SD-WAN can provide functions traditionally delivered by routers, firewalls, IDS/IPS appliances, load balancers, WAN optimizers, SSL VPN concentrators, DNS and DHCP servers, antivirus systems, and network management platforms. The objective is not simply to remove devices. It is to provide multiple network functions through a more integrated and manageable architecture.
A good SD-WAN solution should support administration and management of node appliances from a centralized orchestrator or manager. The orchestrator can manage appliances across geographic regions and propagate application policies across groups of nodes. It can also monitor and upgrade appliances deployed throughout the WAN. This gives administrators a single point from which to manage a large distributed network.
SD-WAN CPE can be deployed as a plug-and-play device without requiring network personnel to perform detailed configuration on site. Once connected, the device can automatically communicate with the Orchestrator and receive its configuration and security policies. A new branch can therefore begin with readily available broadband or wireless connectivity. This prevents long private-circuit provisioning times from delaying branch operations.
MPLS provisioning can take multiple weeks in some scenarios. SD-WAN allows a new location to start with broadband, Internet, wireless, or other readily available connectivity. When the private circuit becomes available later, it can be added to the same WAN architecture. New branch initiatives therefore do not need to be delayed just because the preferred private circuit has not yet been installed.
The proliferation of SDN and cloud computing means applications are no longer permanently tied to one physical data center. Enterprises need network policies that can move with the applications. SD-WAN allows application policies to be updated centrally and distributed across the network. Integration with data-center network controllers through APIs can also help support future software-defined deployments.
SD-WAN can provide granular application and session reports with graphical visualization of the network. Reports can include top talkers, top hosts, top applications, data consumed by each application, and user-level information. This information can be viewed on an aggregate basis and by individual site. Such visibility helps administrators understand how bandwidth is being consumed and how applications are using the WAN.
Interface bandwidth alone does not explain why an application is slow or why a WAN connection is congested. Application and session reports can show which hosts, users, and applications are consuming the available capacity. They can also help identify whether traffic is being distributed appropriately across available WAN paths, allowing network administrators to make policy and capacity decisions using actual traffic information.
The SD-WAN solution should be scalable in terms of device throughput with all required features enabled. Enterprises should consider the number of tunnels required for full mesh, licensing-related throughput, Orchestrator scalability, and concurrent sessions supported by each device. Businesses should also consider future growth in the number of nodes and bandwidth requirements. Scalability should be evaluated beyond only the current network size.
An SD-WAN appliance may perform several network and security functions at the same time. Throughput requirements should therefore consider functions such as WAN optimization, next-generation firewalling, encryption, and other licensed services. The platform must continue to meet the required performance while these services are active. This is particularly important as the network grows and more application traffic is carried through the device.
SD-WAN can identify traffic using traditional Layer 3 and Layer 4 information as well as application information. This allows administrators to apply allow or deny policies based on the actual application instead of depending only on ports and addresses. Restrictive rules can also be applied according to schedules. This provides more granular control over Internet and enterprise traffic passing through the branch.
IDS and IPS functionality can monitor network traffic and alert administrators when potentially hostile activity is detected. These systems collect and analyze information to identify possible security breaches, intrusions, or misuse. IPS can also respond to malicious traffic by blocking a user or source IP address. Integrating these functions with SD-WAN provides more visibility and security at the enterprise edge.
Web filtering can monitor Internet usage and protect users from malware, spyware, viruses, and other Internet threats. It can inspect web access, including SSL/HTTPS traffic where supported, and enforce corporate browsing policies. Content can be controlled using categories, users, groups, URLs, or specific file types. This allows direct Internet access from branches while maintaining centralized policy control.
An emerging enterprise approach is to steer Internet-destined traffic toward Secure Web Gateways. SD-WAN can tunnel traffic to a cloud gateway using GRE or IPSec across multiple WAN connections. Trusted locations can be propagated to branches so selected traffic can bypass the tunnel for more efficient routing. This allows SD-WAN to service-chain with cloud-based firewalls and SWG platforms.
WAN optimization addresses performance limitations that are not solved simply by adding another connection. SD-WAN can provide application-specific optimization, TCP and UDP optimization, congestion-control algorithms, caching, compression, and deduplication. These functions can reduce the effects of latency and repetitive data transfer. They are particularly useful for latency-sensitive applications and constrained WAN connections.
TCP performance can be affected significantly by latency, bandwidth, and congestion behavior. SD-WAN optimization can use multiple TCP congestion algorithms for different types of traffic and different types of links. This can improve performance on high-latency, low-bandwidth links and low-latency, high-bandwidth connections. The goal is to improve utilization of the available WAN capacity.
Satellite connections can provide valuable connectivity but may introduce high latency. SD-WAN optimization can use customized algorithms designed for high-latency links to improve application performance. Traffic policies can also determine which applications should use satellite and which should use other available WAN paths. This makes satellite a practical component of a hybrid connectivity architecture.
Compression can reduce the amount of data that must be transmitted across the WAN. Deduplication can identify repeated data and reduce repeated transmission. Byte-level and file-level caching can improve file transfers and chatty application traffic. If a transfer drops during a transaction, cached information may also reduce the need to restart the complete transfer from the beginning.
Enterprise WANs may use Ethernet, leased lines, DSL, satellite, cable, wireless, 3G, 4G, or other connectivity. SD-WAN optimization should not require one specific carrier or access technology. Link- and provider-agnostic operation allows optimization functions to be used across the connectivity available at each location. This supports a consistent enterprise architecture even when the underlying WAN services differ.
SD-WAN can redirect traffic to the remaining available connection. Because the backup line may have less capacity, application policies can determine which traffic should receive priority. Business-critical applications can continue to operate while lower-priority traffic uses the remaining bandwidth according to policy. This allows the enterprise to maintain service availability even during a partial reduction in WAN capacity.
Multiple WAN connections provide alternate paths when one carrier or access circuit becomes unavailable. Intelligent WAN Routing can move traffic to the healthy connections while maintaining application policies and session continuity where supported. Critical applications can continue using the remaining available bandwidth. This helps reduce the impact of carrier failures on day-to-day business operations.
The ability to maintain session integrity and seamless transition during a WAN failure is crucial for business-critical activity. A database session has to remain connected, a VoIP call cannot be dropped, and production monitoring data may need to continue transmitting. SD-WAN can combine intelligent path selection with stateful failover. This allows the underlying WAN path to change without automatically interrupting the application.
Adding bandwidth does not by itself provide application-aware routing, multiple-path intelligence, session failover, centralized policy, security convergence, or provider independence. SD-WAN uses the available WAN resources more intelligently and directs traffic according to business requirements. It can also combine several types of connectivity instead of depending on one expensive network. The value comes from better utilization, resilience, application performance, and operational simplicity.
The replacement of end-of-life routers with new routers is no longer the only option available when upgrading an enterprise network. SD-WAN can provide routing together with multiple other network functions in a software-defined architecture. It also supports hybrid connectivity, centralized control, application policies, resiliency, and security functions. This provides a broader network upgrade than simply replacing one routing appliance with another.
SD-WAN can use a microservices architecture to provide modular software-defined virtual network functions. When new network features are introduced, additional capabilities can be adopted through modular software functions on the existing platform where supported. This provides more flexibility compared to an architecture in which every new capability requires another dedicated hardware device. It allows the WAN to evolve as enterprise requirements change.
The architecture should support multiple WAN links, hybrid connectivity, intelligent WAN routing, application path control, load balancing, stateful failover, centralized orchestration, and security. It should also support growth in bandwidth, tunnels, concurrent sessions, applications, and branch locations. The WAN should remain usable during access migration and carrier changes. The objective is higher network uptime, enhanced application performance, and improved business productivity.
SD-WAN appliances can provide restrictive firewall policies for branch offices. By default, inbound sessions originating externally can be blocked unless they are specifically permitted by a policy. Outbound sessions can also be restricted based on Layer 3, Layer 4, and Layer 7 information. Traffic can be identified using protocol, source and destination IP, port, DSCP values, and application information.