Guide · Networks
SD-WAN or site-to-site VPN: how do you connect several sites?
A site-to-site VPN is an encrypted tunnel over the internet between the firewalls of two locations, so that their networks work as one. SD-WAN is a management layer on top of such connections: it uses several lines per site, measures their quality and steers each application over the best one, all configured centrally. For a few sites with one line each, a site-to-site VPN is usually enough; SD-WAN earns its cost with more sites, several lines per site, or applications such as telephony that cannot tolerate a poor connection.
What is a site-to-site VPN?
The firewall or router at each site sets up an encrypted tunnel, usually with IPsec, to the other site over an ordinary internet line. Traffic between the sites travels through the tunnel, and users notice nothing. Tunnels are configured per pair of sites: every branch to the head office, or every site to every other, in which case their number grows quickly.
Almost every business firewall supports it, and the technology is well understood. The limits: each tunnel is set up by hand, a second line as fall-back has to be built and tested separately, and the tunnel tells you nothing about how well an application is performing.
What does SD-WAN add?
SD-WAN stands for software-defined wide-area network.
- Several lines per site in use together: fibre, a second provider, 4G or 5G.
- Continuous measurement of each line: packet loss, delay and variation in delay.
- Rules per application: telephony over the steadiest line, back-ups over the cheapest.
- Switch-over when a line gets worse, not only when it fails.
- Central management: one policy for all sites, and a new site added without an engineer travelling.
- Often, direct access to cloud services from each site, not through the head office.
Underneath, most SD-WAN products still use encrypted tunnels. SD-WAN is not the opposite of a VPN; it is VPN with a control system on top.
Which one fits your situation?
- A few sites, one line each. A site-to-site VPN.
- Many sites, or more to come. SD-WAN: central management saves work and mistakes.
- Sites that cannot be offline. Two lines per site, which SD-WAN uses to the full.
- Poor calls and video meetings. SD-WAN helps, provided there is a second line to steer to.
- Everything in the cloud. You may need little between the sites: a good line per site and secure remote access.
Private lines such as MPLS, with quality agreed in the contract, remain an option where an application demands it.
What does neither of them solve?
- A poor line stays poor. Steering traffic needs something better to steer to.
- Two lines in the same duct, or resold from the same network, fail together.
- A tunnel encrypts traffic between sites; it does not inspect it. An infected computer at a branch reaches the head office through the tunnel unless firewall rules and segmentation stop it.
What do you ask a supplier?
- Is the licence a subscription, and what does the equipment still do if it is not renewed?
- Who manages the policy, and can we see the configuration?
- Is the switch-over tested at handover, while we watch?
- Where does the management platform run, and what happens at the sites when it cannot be reached?
- Are we tied to one internet provider?
We map the lines and contracts first, and design from there: see WAN infrastructure.
Frequently asked questions
Is SD-WAN more secure than a VPN?
Not in itself. Both encrypt the traffic between sites. Many SD-WAN products include firewall functions and apply one policy everywhere, which reduces configuration mistakes, but the security still depends on the rules that are set.
Does SD-WAN replace MPLS?
It can, and it is often bought for that reason. An internet line comes without the agreed quality of a private line; SD-WAN compensates by combining several lines. Where an application needs guaranteed quality, some companies keep a private line for that traffic alone.
Can we keep our existing firewalls?
For a site-to-site VPN, usually yes, also between different makes, because IPsec is a common standard, although settings have to be matched with care. SD-WAN generally requires equipment from the same vendor at every site.
Do people working from home need SD-WAN?
No. SD-WAN and site-to-site VPN connect locations. Someone working from home or on the road uses remote access from the laptop itself, protected by a second sign-in factor.
Let's talk about your project.
Tell us where you are and where you want to be. We'll come back within one working day with a first view. A person reads your message and answers it.