Is it possible to do SD-WAN using the router or firewall? Let's look at Policy-based routing, SLA-based networking, and SD-WAN networking.
Policy-based routing can direct traffic over multiple links across a network based on rules or filters. PBR allows admins to use source IP address, destination port, protocol type, traffic type, and access control list (ACL) entries. By defining policies based on these criteria, they can prioritize traffic on links by application, such as VoIP or video, distribute traffic across multiple links, steer traffic away from suspicious sources, or block specific types of traffic. PBR requires a router with this capability and policies must be configured on each device. PBR is typically based on pre-defined static rules. Using tools like IP SLA on Cisco routers provides alerts and data to guide a response.
Service-level agreement networking adds a reactive capability. The location can be served by two or more WAN connections. Policies can be configured for failover from one link to another link if packet loss, jitter, or latency exceeds a threshold. Policies can be set up to steer traffic over specific links for traffic types. The failover is active/passive so the second link is not always in use. Policies must be configured on each device. External monitoring tools detect policy violations and enforce them by changing PBR rules on the device. SLAs are typically established and implemented by the service provider that provides the WAN connections based on an agreement between them and the organization using the links.
SD-WAN combines the capabilities of PBR and SLA and adds functionality. It can steer traffic over multiple links in active/active mode. It has built-in policies for common applications. It can fail over faster than other methods. Packet replication and forward error correction improve performance on congested links. It uses a dedicated SD-WAN edge device in addition to the router and firewall but might provide limited routing and firewalling. Central management is used to push policies to all devices. Visibility and monitoring functionality are included with the management system. This aids in networking tuning and troubleshooting. The organization can deploy SD-WAN or it can be obtained as a managed service.
It is possible to create some of the capabilities of SD-WAN using the router and/or firewall with limitations. With PBR and SLA methods each device must be configured. There is no central orchestrator. There are no built-in policies. Visibility, monitoring, and automation capabilities are delivered by external systems. SD-WAN provides centralized management, built-in policies, automation, and visibility and monitoring.
Organizations that have been using PBR and SLA are migrating to SD-WAN to increase functionality and reduce administrative overhead. Eventually, SD-WAN will be a part of the routing function and devices will converge.
#sdwan #pbr #sla #routing #firewall