Technical deep dive: SD-WAN, ZTNA, and proxy technologies

A technical guide to how SD-WAN, ZTNA, and proxy technologies work individually and how they integrate into a unified secure access architecture.

Enterprise networks face three interconnected challenges: connecting distributed sites efficiently, securing application access without exposing the underlying network, and protecting users from web-borne threats. SD-WAN, ZTNA, and proxy technologies address these problems individually and as an integrated system.

SD-WAN

SD-WAN (Software-Defined Wide Area Network) connects distributed sites and branch offices using intelligent software rather than relying solely on MPLS circuits. Traffic routes across any available transport including broadband, 4G/5G, and dedicated internet access.

Routing decisions are made by classifying traffic by application using deep packet inspection. Each data flow is then routed based on application requirements such as latency sensitivity and bandwidth needs, real-time link quality metrics including jitter and packet loss, security policies such as encryption requirements and approved paths, and whether a link degrades or fails – in which case traffic automatically shifts to alternative paths without disrupting active sessions.

The practical consequences are significant. Sites can go live in days using readily available internet circuits. WAN costs typically decrease substantially by replacing or supplementing MPLS with cheaper alternatives. Application performance improves through intelligent path selection, and configuration changes deploy centrally in minutes. SD-WAN also includes integrated security features including IPsec encryption, firewall capabilities, and direct cloud access for SaaS applications.

For a full overview of SD-WAN architecture and deployment, see our SD-WAN guide.

ZTNA

Zero Trust Network Access provides secure application access without exposing the network itself. Traditional VPNs grant broad network access once a user authenticates. ZTNA grants access to specific applications only, making the underlying network infrastructure invisible to the connecting user.

When a user attempts to access an application, the following sequence occurs:

  1. The user authenticates against the identity provider (Azure AD, Okta, or equivalent)
  2. The ZTNA controller evaluates user role, device compliance, location, and time of access
  3. The system checks all conditions against defined security policies
  4. If approved, a micro-tunnel connects the user directly to that specific application
  5. The network remains hidden; users cannot discover other applications without explicit permission

Modern ZTNA platforms integrate with existing identity systems, evaluate device posture continuously, and produce detailed audit logs of all access attempts. The VPN vs ZTNA comparison diagram illustrates the architectural difference.

For more on zero trust principles and how ZTNA fits within a broader zero trust architecture, see our zero trust guide.

Proxy technologies

Proxy technologies sit between users and the internet, inspecting traffic to enforce security policies and block threats. Web proxies act as intermediaries for HTTP and HTTPS traffic, evaluating every request against security rules before forwarding approved traffic.

The security functions proxies provide include URL filtering against threat intelligence feeds, content scanning for malware before it reaches user devices, data loss prevention by inspecting outbound traffic for sensitive information, acceptable use policy enforcement, and complete activity logging for compliance and forensic purposes.

A Secure Web Gateway (SWG) extends the traditional proxy model by operating from distributed cloud locations rather than on-premises appliances. Users connect to the nearest cloud point of presence, which enforces security policies before permitting internet access. This cloud-delivered model ensures consistent protection regardless of where users are connecting from. For more detail on SWG architecture, see our Secure Web Gateway guide.

How the three technologies integrate

The three components work as a coordinated system. When a branch office user accesses different resource types, the routing and inspection happens automatically in the background.

For internal application access, SD-WAN routes traffic to the cloud security stack, ZTNA verifies identity and device compliance, and a secure connection is established to the specific application. For internet browsing, SD-WAN recognises web traffic, routes it through proxy services, content is inspected and policies enforced, and approved traffic is forwarded. For SaaS applications, SD-WAN provides direct internet breakout, the proxy inspects traffic, and the path is optimised to the cloud service.

The integration delivers several operational advantages. Security policies remain consistent regardless of user location or connection method. ZTNA gains context from device posture tags and policy. Proxy inspection can trigger additional authentication if suspicious patterns are detected. New sites and users are added through centralised management without additional complexity.

Deployment considerations for hybrid environments

Network topology

Three primary architectures suit different requirements. Hub-and-spoke routes all traffic through central data centres, providing strong security controls but introducing potential bottlenecks. Full mesh enables direct site-to-site connectivity for better performance but increases management complexity. A hybrid design routes security-sensitive traffic through centralised inspection while direct connectivity handles routine application access – the most common choice for organisations with mixed requirements.

Cloud-first requirements

Cloud-first environments require direct internet breakout from branches for SaaS applications, with cloud-delivered security services handling inspection. Private connectivity to AWS and Azure supports workloads requiring consistent latency or compliance guarantees.

Cloud-delivered security with points of presence near users optimises performance. Integration between SD-WAN edge devices and cloud security inspection services ties the architecture together.

Policy design

Effective policies separate concerns into four layers: network policies defining which sites can reach which resources; security policies specifying inspection and controls for different traffic types; ZTNA policies determining who can access which applications under what conditions; and logging and telemetry policies enforcing regulatory and compliance requirements for data handling and retention.

This separation makes policies easier to audit, modify, and troubleshoot independently.

Regulated sector considerations

For NHS organisations and government bodies, the integration of SD-WAN, ZTNA, and proxy technologies addresses specific compliance requirements directly. SD-WAN can route HSCN and PSN traffic through appropriate paths with the required security controls applied. ZTNA restricts access to clinical and sensitive government systems to verified users on compliant devices, with every access attempt logged. Proxy inspection enforces the acceptable use and data handling requirements that DSPT, CAF, and PSN assessments expect to see evidenced continuously.

The audit trail produced by all three technologies operating in combination – access logs, routing records, policy enforcement events – is considerably easier to present at compliance review than the equivalent assembled from multiple separate point solutions.

Migration from legacy infrastructure

Successful migration from traditional VPN and MPLS requires phased implementation that minimises risk while building operational capability.

A recommended sequence begins with a pilot programme validating technology choices against two or three non-critical sites, followed by operational validation covering monitoring, troubleshooting, and change management procedures. Sites then deploy in waves based on complexity and criticality, with old and new systems running in parallel during transition. Legacy infrastructure is decommissioned once the new platform has demonstrated stability.

Setting realistic performance expectations matters. TLS inspection adds five to twenty milliseconds of latency depending on implementation. ZTNA authentication occurs per session but requires identity system availability. SD-WAN path selection responds to real-time conditions but cannot overcome the underlying limitations of a circuit.

Long-term success depends on team readiness: training on the integrated architecture, documented runbooks for common scenarios and troubleshooting steps, and monitoring that spans all layers to surface issues before users notice them.

The unified architecture

SD-WAN, ZTNA, and proxy technologies function most effectively as an integrated platform rather than three separate products that happen to coexist. This convergence defines a unified model, where networking and security combine into a single cloud-delivered service with a unified control plane providing visibility across the entire estate.

For organisations navigating hybrid cloud environments, supporting distributed workforces, or modernising legacy infrastructure to meet compliance requirements, the integrated architecture provides the foundation. The control plane gives unified visibility. Policy is consistent. Deployment is automated. The result is connecting users and applications securely, efficiently, and at scale.

Cloud Gateway delivers SD-WAN, ZTNA via Secure Private Access (SPA), and Secure Internet Access (SIA/SWG) as part of a single managed platform. For more on how these capabilities work together, see our platform page and our SD-WAN product page.

Head of Product Engineering

Ben Rees

Related Articles

Want to know more about how we work?