What is Software-Defined Wide Area Network (SD-WAN)?
SD-WAN uses a software-controlled policy layer to steer WAN traffic across one or more underlays such as broadband, cellular, and MPLS. It can measure path health and select paths by application or policy. Encryption and security inspection depend on the implementation. SD-WAN alone is not SASE. Evaluate path selection, underlay diversity, policy, observability, failure behavior, and security integration.
Why it matters
Organizations often use several WAN connections with different cost, latency, and reliability. SD-WAN can apply consistent path policy and move application traffic when path conditions change.
How it works
- Edge devices create an overlay across available WAN underlays and identify application traffic.
- A control layer distributes path and application policy to the edges.
- The edges measure path health and steer each traffic class to an allowed path.
Example
A branch sends voice traffic over a low-latency MPLS path and moves it to broadband when health checks show that the primary path has failed.
Pomerium boundary
Pomerium operates at the application access layer and can run across networks that use SD-WAN. Pomerium does not control WAN underlays or select paths between branch and cloud networks.
Limits and non-claims
- SD-WAN still depends on the capacity and availability of its underlying network connections.
- Encryption, inspection, and segmentation differ by implementation and are not implied by the SD-WAN label.
- Controller, edge, or policy errors can move traffic to an unsafe or unsuitable path.
Evaluation checklist
- Which branch, controller, overlay, underlay, routing, authentication, and encryption components carry traffic?
- Which identity-aware and application permissions remain after SD-WAN establishes reachability?
- Can controller compromise, branch key theft, local Internet breakout, or failover bypass inspection?
