Skip to main content

Software-Defined Networking (SDN)

Software-defined networking separates programmable control functions from the packet-forwarding plane through defined abstractions and interfaces.

What is Software-Defined Networking (SDN)?

Software-defined networking is a programmable-network approach that separates control functions from the packet-forwarding plane through abstractions and interfaces. Software applications can initialize, control, change, and manage network behavior, while forwarding elements apply programmed packet-handling rules. SDN does not require one centralized controller, one protocol, or software-only forwarding hardware.

Why it matters

A programmable control layer can apply network changes consistently and can reduce device-by-device configuration. It can also connect network state to automation for provisioning, path control, and segmentation.

How it works

  1. Network devices expose forwarding and operational resources through an abstraction and control interface.
  2. Control applications calculate desired network behavior and program the applicable forwarding elements.
  3. The forwarding plane handles packets and returns state or telemetry to the control and management layers.

Example

An SDN controller updates virtual-switch forwarding rules to isolate a compromised workload while the other tenant networks continue to operate.

Pomerium boundary

Pomerium is an identity-aware application proxy, not an SDN controller. It can protect applications that run on an SDN-managed network, but it does not program router or switch forwarding planes.

Limits and non-claims

  • A controller or policy error can affect many forwarding elements at the same time.
  • An abstraction or open interface does not guarantee interoperability, correct policy, or safe failure behavior.
  • Packet-forwarding policy does not replace identity-aware authorization for actions inside an allowed application.

Evaluation checklist

  • Which controller identities and policy inputs program each data-plane device?
  • How do devices verify configuration integrity, version, and controller authority?
  • Can controller compromise, stale state, local override, or control-plane outage change effective forwarding?

Sources and further reading

Keep learning

Zero TrustNetwork and Infrastructure

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo