The traditional approach to WANs involves placing physical devices at sites that are connected via various data connectivity to Internet providers. At these facilities, IPSEC tunnels were configured to "connect" remote offices to the central office. The encrypted connection ensured the privacy of the communication.
The Cisco SD-WAN solution is based on a central management system, through which the entire solution is managed. Individual sites are automatically connected to the network, without the need to configure the device. Using templates and automation scripts, devices can be centrally managed. Thanks to the central management, the end devices focus only on sending data, all decision-making and management is handled by dedicated elements located in the customer's network or in the cloud.
Pillars of SD-WAN:
- Controller (SD-WAN Controller): this is the central element that controls and manages the entire SD-WAN network. It provides basic functions such as policy management, traffic routing, cloud connectivity and network traffic monitoring.
- SD-WAN Edge: This is a network device (hardware or virtualized) that resides at individual branch offices or remote locations. The SD-WAN Edge provides connectivity to the customer's network over the provider's line(s), shares traffic information with the SD-WAN Controller, and performs intelligent traffic routing.
- Security: Cisco SD-WAN also includes security features such as firewall, data encryption and malware protection.
The solution can be implemented on ISR 4xxx, ISR 1000, C8000 and C8000v series routers
Central vManage can be installed in a local network or cloud environment