Networking
The full domain, and the other capabilities within it.
Make the branch network something you configure centrally and reason about once.
Software-defined WAN puts an overlay across whatever transport each branch has — broadband, LTE, private circuit — and selects the path per application against measured link quality. SD-Branch extends the same central control to the branch LAN, wireless and security stack.
The business case is usually cost: replacing or supplementing expensive private circuits with broadband. The operational case is often larger — a hundred branches configured from policy rather than one at a time.
If more than one of these is true, this is usually the right place to start.
| Deliverable | What it contains |
|---|---|
| Site classification | Branches grouped by size, criticality and application profile, with a transport and hardware pattern per class. |
| Policy design | Application groups, path preference, thresholds for steering, and behaviour under brownout as well as failure. |
| Security design for breakout | What inspection and filtering follows the traffic when it stops passing through the data centre. |
| Rollout plan | Pilot, wave plan, per-site runbook and rollback, with the criteria that must be met before the next wave. |
A reference, not a template. Your estate decides which parts apply and in what order they arrive.
Targets are agreed with you before the work starts, and reported against for its duration.
Often it lets you reduce them rather than remove them: broadband plus LTE as the primary pair, with a private circuit retained where an application genuinely needs guaranteed latency. The site classification is where that gets decided honestly.
Only with the security design done first. Breakout removes the data-centre inspection path, so the controls have to follow the traffic — cloud-delivered security or an on-site stack. Breakout enabled without that decision is the most common mistake here.
It extends the same central management to the branch LAN, wireless and security instead of just the WAN edge. The value is operational: one policy model and one console rather than four.
That is the case it handles better than traditional routing, which mostly sees up or down. Path selection works on measured loss, latency and jitter, so a brownout moves traffic before users start complaining.
Yes, and you should. The overlay coexists with existing routing, so sites move in waves behind a pilot, with the exit criteria for each wave agreed in advance.
Yes. Central policy makes routine change easier; it does not remove the need to understand what the network does when something breaks. The handover assumes your team will operate it.
The full domain, and the other capabilities within it.
802.1X, device profiling and posture-based access — deployed in monitor mode first, so enforcement is based on what is actually on your network.
Discovery, telemetry and alerting tuned so that an alert means something — with thresholds set from observed baselines rather than defaults.
The fastest way to a useful answer is a short, scoped look at what you already have.