What is SD-WAN? A complete guide

SD-WAN separates network control from the underlying transport, enabling intelligent traffic routing across multiple circuits and locations. This guide covers what SD-WAN is, how it works, and what it means for regulated organisations modernising their network estates.

What is SD-WAN?

Software-Defined Wide Area Network (SD-WAN) is a networking approach that separates the control of network traffic from the physical infrastructure carrying it. Rather than configuring each network device individually at each site, SD-WAN places an intelligent software layer over the underlying circuits – broadband, MPLS, 4G/5G, or any combination – and manages how traffic moves across them from a central management point.

The result is a WAN that can be managed as a whole rather than as a collection of individually configured sites, with the ability to route traffic intelligently based on application requirements, circuit quality, and defined policy.

How SD-WAN works

Traditional WANs route traffic based on static configuration: a packet goes to its destination via a fixed path, and changing that path requires manual reconfiguration of network devices. For large multi-site estates, this creates significant operational overhead and limits how quickly the network can adapt.

SD-WAN works differently. An SD-WAN controller – which can be cloud-hosted or on-premises – holds the network’s policy and routing logic centrally. Edge devices at each site receive and enforce that policy, making real-time routing decisions based on current circuit performance.

When a clinician accesses an electronic patient record system, the SD-WAN edge at their site assesses the available circuits, identifies which one is performing best for that application at that moment, and routes the traffic accordingly. If one circuit degrades or fails, traffic shifts to an available alternative automatically, without manual intervention. The same logic applies to every application across the estate, with different policies applied to different traffic types based on their sensitivity and performance requirements.

This is the core capability that makes SD-WAN valuable for organisations with complex, multi-site estates: the network responds dynamically to conditions rather than following fixed paths that may or may not be appropriate at any given time.

SD-WAN architecture

An SD-WAN architecture has three principal elements.

The overlay network is a software-defined layer that creates secure, encrypted tunnels between sites and cloud environments, independent of the underlying transport. Traffic flows through the overlay regardless of which physical circuit is carrying it.

The edge devices are the on-site hardware or virtual appliances that connect each location to the SD-WAN fabric. They implement the routing policies set centrally and handle the real-time path selection decisions.

The centralised controller is where policy is defined and where visibility across the estate is aggregated. Changes made at the controller propagate to all edge devices across the estate, eliminating the need to touch each site individually.

This separation – overlay from transport, policy from device – is what gives SD-WAN its operational flexibility. The underlying circuits can be a mix of technologies and providers. The policy and management layer is consistent across all of them.

SD-WAN and security

SD-WAN and security are increasingly inseparable. A standalone SD-WAN that handles routing without security policy is operationally incomplete for most regulated organisations. The more useful question is how security integrates with the SD-WAN fabric.

Secure SD-WAN integrates security capabilities directly into the SD-WAN architecture rather than requiring separate security appliances at each site. Firewall policy, intrusion detection and prevention, and web filtering are applied at the SD-WAN edge, with policy managed centrally alongside the routing policy. For regulated organisations running multi-site estates, this means consistent security posture across all locations from one management layer, with evidence generated centrally rather than assembled site by site.

The relationship between SD-WAN and SASE is relevant here. SASE (Secure Access Service Edge) combines the SD-WAN connectivity layer with cloud-delivered security services under one architecture. SD-WAN is the network component; SASE is what results when security is added to it in a genuinely integrated way. Our SASE guide covers this in more detail.

SD-WAN compared to MPLS

MPLS (Multiprotocol Label Switching) has been the dominant enterprise WAN technology for two decades. It offers guaranteed bandwidth and quality of service, but carries high per-site costs, long provisioning lead times, and limited flexibility once in place. Adding or changing sites requires carrier involvement and can take weeks or months.

SD-WAN can run over MPLS, but it can also run over broadband, 4G/5G, and other lower-cost circuit types – routing traffic intelligently across whichever circuits are available and performing best. Organisations moving from pure MPLS to SD-WAN typically reduce WAN costs significantly, while maintaining or improving application performance through active path management.

SD-WAN also supports hybrid deployments: MPLS for latency-sensitive or compliance-critical traffic, broadband or mobile for less demanding applications. The mix can be adjusted over time as requirements change and as MPLS contracts come up for renewal.

SD-WAN for regulated organisations

For NHS organisations, government departments, and policing, SD-WAN has particular relevance to three problems.

Multi-site management at scale. A hospital trust managing dozens of sites, a police force connecting stations across a county, or a local authority linking offices and community centres all face the same challenge: consistent connectivity and policy across a geographically dispersed estate. SD-WAN’s centralised management reduces the operational overhead of running that estate significantly.

Compliant connectivity to regulated networks. HSCN and PSN both require that the architecture of the connection meets specific standards. SD-WAN that is designed to connect into HSCN and PSN – rather than bolted on afterwards – makes compliant multi-site connectivity considerably more manageable. The edge device at each site becomes the compliant access point to the regulated network, with policy applied consistently across all sites.

Evidence for compliance. CAF and DSPT assessments require organisations to demonstrate that their network is managed and governed appropriately. SD-WAN’s centralised visibility means that performance data, configuration history, and change records are available from one place, rather than being assembled from individually managed devices across the estate.

Cloud connectivity

Modern SD-WAN solutions provide optimised connectivity to cloud environments alongside site-to-site connectivity. Direct cloud on-ramps, also called SD-WAN fabric extensions to cloud providers, create private paths from the SD-WAN overlay into AWS, Azure, or Google Cloud, bypassing the public internet for cloud-bound traffic and improving both performance and security.

For organisations running hybrid cloud and on-premises workloads, SD-WAN’s ability to manage traffic across both environments under one policy layer is a practical advantage. Cloud-hosted applications receive the same quality-of-service treatment as applications running in data centres, with routing decisions adapting dynamically to performance conditions.

Deployment and transition

SD-WAN supports phased deployment, which matters for organisations transitioning from existing WAN infrastructure. Sites can be migrated progressively rather than simultaneously, with the SD-WAN overlay running alongside existing circuits during the transition period. Zero-touch provisioning allows new sites to be connected quickly once the central controller is configured, without requiring on-site technical resource for the initial setup.

For regulated organisations with estates that cannot tolerate disruption to live services, the ability to run SD-WAN alongside existing infrastructure during transition is particularly important.

How Cloud Gateway delivers SD-WAN

Cloud Gateway delivers SD-WAN as part of the Business Everywhere product family, combining the SD-WAN overlay with the underlying circuit provision and managed security under one operating model. Connections to HSCN, PSN, and cloud environments are built into the same managed service rather than requiring separate arrangements.

The service is operated from the UK, by UK-based engineers, with the governance and compliance evidence that NHS, government, and policing environments require. For more on how this works, see our Modernise your network page and Business Everywhere: SD-WAN.

Related Articles

Want to know more about how we work?