Sie sind auf Seite 1von 5

SD-WAN for Enterprises

VMware Special Edition


Enterprise wide-area network (WAN) software-defined networking (SDN)
technologies have changed little, if at all, architecture beyond the data center to
in the last couple of decades. Traditional the enterprise WAN. SD-WAN abstracts
WANs utilize rigid architectures, which network hardware into a control plane
are optimized around private data center and multiple data planes that can be used
applications. These architectures are with cloud-based management and
unable to seamlessly integrate cloud automation to virtualize enterprise WAN
computing, Software as a Service (SaaS), connections and simplify the delivery of
virtualization, and other technological services between remote and branch
advances. Branch offices with only private- offices to data centers and the cloud.
circuit connections rely on backhauling of
all cloud applications, SaaS, and Internet Enterprise WAN Challenges:
traffic through the enterprise data center, Expensive, Complex, and
adding latency, degrading application Inefficient
performance, and driving up network
Traditional enterprise WAN architectures
bandwidth costs.
are complex, inefficient, and expensive.
A software-defined wide area network These WANs are typically built with private
(SD-WAN) extends the benefits of the multiprotocol label switching (MPLS)
connections that are highly reliable The Essential SD-WAN for
but expensive. These connections are the Enterprise
often supplemented with unreliable,
An ideal SD-WAN platform should include
but inexpensive Internet connections,
three components that provide enterprises
such as broadband or Long-Term
with an optimized platform to deliver
Evolution (LTE). Legacy WAN operations,
high-performance, reliable branch access
such as bringing up a branch office,
to cloud services, private data centers,
are slow and labor-intensive. Network
and SaaS-based enterprise applications.
devices, such as routers and switches,
The recommended components of an
must be purchased, installed, provi-
SD-WAN solution include the following:
sioned, and configured by skilled on-site
network engineers and WAN access lines
•O
 rchestration: A cloud-delivered,
must be connected. Additionally, branch
multitenant portal providing
traffic is often backhauled to a private
centralized management, configura-
data center or headend, which introduces
tion, monitoring, and troubleshooting.
inefficiency, complexity, cost, latency,
The orchestrator provides the ability
and application performance issues.
to deliver business-driven policy
abstraction, enabling rapid deploy-
Research by VMware found
ments and zero-touch operations.
that packet loss in traditional
enterprise WANs varied up to Additionally, it exposes a rich set of
12.5 percent over 24 hours. The application programming interfaces
performance impact of packet loss is (APIs) that provide management,
high: During a file transfer with 0.5 troubleshooting, and operations
percent packet loss, Transmission support system/business support
Control Protocol (TCP) throughput system (OSS/BSS) integration.
drops from 10 megabits per second
(Mbps) to 1 Mbps. For real-time traffic, • SD-WAN gateways: Deployed by the
the mean opinion score (MOS) drops SD-WAN provider and its partners at
from 4.5 to 2.5. (MOS scores range top-tier network points of presence
from 1 [unacceptable] to 5 [excellent].) (PoPs) and cloud data centers around
the world, SD-WAN gateways provide a platform to rapidly and efficiently
scalable and distributed infrastructure scale WAN services.
with the advantages of cloud-delivered,
multitenant network as a service •S
 D-WAN edge: SD-WAN edges are
(NaaS) flexibility. They also provide available as easy-to-install appliances
the ideal architecture for optimized for remote branches and data centers
access to cloud applications and data with a range of throughput, interfaces,
centers, as well as access to private integrated wireless, and LTE connec-
network backbones and traditional
tivity options. Edges support dynamic
enterprise sites.
underlay and overlay routing. They
can be inserted in-path or off-path in
SD-WAN gateways play two indepen-
an existing network. High-availability
dent roles (referred to as planes), each
deployments are also supported. The
providing separation of services: the
control plane and the data plane. The SD-WAN edge receives all policies
control plane provides a number of and configurations from the SD-WAN
important functions, including discovery orchestrator, classifies traffic using a
of link bandwidth and IP addresses, deep-packet application recognition
and route information distribution (DAR) engine and applies policies
and updates. When the gateway is based on real-time link quality. Traffic
participating only as a control plane steering decisions are made locally
element, its role is referred to as the on the SD-WAN edge. SD-WAN edges
SD-WAN controller. When the SD-WAN
may be deployed with infrastructure
gateway’s data plane capability is
as a service (IaaS) environments such
enabled, its role serves as a multitenant
as Amazon Web Services (AWS) or
SD-WAN endpoint for SaaS on-ramp
Microsoft Azure. SD-WAN edges are
and service provider integration. SD-
typically available in two form factors:
WAN gateways are stateless elements,
designed to be highly scalable hardware appliance and virtual
and allowing for quick expansion and appliance. Both form factors support
recovery. Both the control plane and a broad range of throughput,
the data plane provide a unified interface, and connectivity options.
Key Capabilities and Main •E
 nterprise-wide business policies:
Features of SD-WAN SD-WAN makes setting policy as
simple as a single click. Enterprises or
Key capabilities of SD-WAN for
their managed service providers can
enterprises include the following:
define business-level policies that
apply enterprise-wide across many
•F
 lexible overlay topologies,
edges, all through a centralized, cloud-
options, and deployment models:
based orchestrator. Link steering, link
SD-WAN orchestrators and SD-WAN
remediation and Quality of Service
gateways are deployed as software-
(QoS) are all applied automatically
only entities. SD-WAN edges can be
based on set business policies;
deployed as virtual (software) or as
however, specific configuration
hardware appliances. The hosted
overrides may also be applied. A
SD-WAN orchestrator and SD-WAN
centralized SD-WAN orchestrator also
gateways are usually deployed in a
provides an enterprise-wide view and
virtual form in either public clouds,
configurability of routing in an overlay
such as AWS or Microsoft Azure, or
flow control table, eliminating complex
through large Internet service provider
node-by-node route configurations.
(ISP) data centers for optimal access
for the users. •U
 nified, robust security: SD-WAN
provides unified, secure communica-
•A
 ssured application performance: tions for traffic steered across any
SD-WAN boosts the service level and underlying transport. Standard
capacity of hybrid networks or Internet Protocol Security (IPsec)
standard broadband Internet links encryption is provided end to end
by implementing optimization tech- from branches to data centers and
nologies that include continuous for dynamic branch-to-branch
monitoring, dynamic application communications. A cloud-delivered
steering, on-demand remediation, architecture also provides an auto-
and Quality of Experience (QoE). matic virtual private network (VPN)
from branches-to-cloud gateway Check out the following
aggregation points for interoperable resources from VMware to
access to infrastructure as a service learn more about SD-WAN:
(IaaS), eliminating manual, two-sided •V
 Mware SD-WAN by VeloCloud website
tunnel setup from 1xN branches to
• SD-WAN Overview For Dummies iPaper
1xN cloud data centers. The solution
•S
 D-WAN Deployment For Dummies iPaper
should provide the scalability and
•S
 D-WAN Future For Dummies iPaper
robust security of a public key infra-
• SD-WAN For Dummies e-book
structure (PKI) with the consolidated
management of an integrated
certificate server, secure onboarding
of devices, and revocation manage-
ment. Risk is minimized by pinning
certificates to specific devices and
using unique pair-wise encryption keys.

•Q
 uick deployment in minutes:
Using the zero touch deployment
capability, an SD-WAN edge can be
quickly installed. The SD-WAN edge is
shipped to the branch office where a
nontechnical person simply plugs in
power and a network cable. Activation,
configuration, and ongoing manage-
ment are all handled from the cloud.

For Dummies is a trademark of John WiIey & Sons, Inc. ISBN: 978-1-119-68773-3

Das könnte Ihnen auch gefallen