It typically creates an overlay across underlays such as broadband, cellular, Carrier Ethernet, or Multiprotocol Label Switching (MPLS), then selects paths according to application and network conditions.
SD-WAN edges classify traffic, establish overlay connectivity, measure paths, and apply forwarding policies. A controller or orchestrator distributes configuration and policy while forwarding devices move traffic locally. Implementations differ in topology, interoperability, encryption, security inspection, and operating responsibility.
Key points
Path controlEdges can classify applications, measure paths, select routes by policy, fail over, and perform traffic engineering across available underlays.
OperationsCentral policy distribution and zero-touch provisioning can make geographically distributed sites easier to configure consistently and observe.
Service scopeSome offerings add encryption or security inspection, but buyers must verify those functions and where they are enforced; they are not inherent to every SD-WAN.
Important limitationMultiple links do not guarantee independent failure paths or predictable end-to-end performance. Shared carriers and physical routes can create common points of failure, and centralized management or edge compromise can propagate incorrect policy across many sites.