Cisco · Infrastructure · YoctoIT tech page

SD-WAN

The software-defined WAN: branch traffic routed by policy — the right line for each application, the cloud within direct reach.

FOCUS · THE INTELLIGENT WANThe end of backhauling: cloud traffic exits directly, the critical travels protected
YoctoIT material for clients and partners · Cisco, Meraki, Splunk, Duo and the other products mentioned are trademarks of Cisco Systems, Inc. or its affiliates.
01 · What it is

Catalyst SD-WAN, made clear.

Catalyst SD-WAN (Viptela) replaces the rigid WAN: several lines per site (MPLS, internet, 5G) used together, with applications routed by policy — the ERP on the guaranteed line, the cloud straight out on local internet, failover in milliseconds. The WAN is governed centrally and adapts by itself.

App-aware
the routing recognizes the applications: each traffic on the right path
50 ms
the failover between lines: the branch doesn't notice the failure
DIA
Direct Internet Access: the cloud without the detour via the data center
Catalyst SD-WAN
OFFICIAL CISCO BRANDING · SD-WAN
CONSOLE REALE · CATALYST SD-WAN MANAGER · FONTE: CISCO
REAL CONSOLE · CATALYST SD-WAN MANAGER · SOURCE: CISCO
02 · How to use it well

The things that make the difference.

The policy-driven WAN

Branches and siteseach with 2+ lines
MPLS
Internet
4G/5G
the paths, all used
vManage · central policiesthe intent, distributed
Cloud & data centerthe destinations, direct
The traffic where it pays, not where it lands

Traffic assessment

What really travels on the WAN: the snapshot that shapes the policies (and often cuts the MPLS).

Migration in waves

The sites converted in groups, with rollback: the WAN gets changed with the engine running.

Integrated security

The security stack (or SASE with Umbrella) on the local exit: DIA without exposing the branches.

Measured SLAs

Loss, latency and jitter per application: the carrier challenged with charts, not feelings.

03 · In depth

Overlay, application policies and the WAN that chooses

Catalyst SD-WAN separates control plane (vSmart) and data plane (edge routers): the OMP overlay builds tunnels over MPLS+internet+5G, application policies route by SLA (voice on the best line NOW), App-Aware Routing measures loss/latency/jitter continuously, the cloud onramp optimizes the route to M365/SaaS/IaaS, the integrated security (or SSE with Umbrella) protects the local breakout.

  • App-aware routing — the application on the line that honors the SLA, measured in real time
  • Transport independence — MPLS, FTTH, 5G in the same overlay: the carrier becomes a commodity
  • Cloud onramp — the optimal route to M365 and SaaS: the smart local breakout
  • Segmentazione — VPN/VRF per department or company: multi-tenant on the WAN
  • Zero-touch — the branch switched on by itself: the router enrolls and downloads everything
  • SSE ready — Umbrella/SIG on top of the breakout: security follows the user
04 · Numbers and lifecycle

The numbers that matter.

-40%
the typical WAN TCO vs pure MPLS
0-touch
branch provisioning
real-time
the per-path metrics: the SLA verified, not promised
min
the failover between transports: the branch doesn't notice
The modern WAN is policy, not circuits: design, migration in waves and operations from our NOC — the branches that don't call anymore.
05 · Use cases

Where it really pays off.

Branch networks

Dozens of sites, reduced MPLS, fast cloud.

Fast M&A

The acquired site hooked up in days.

Critical sites

Dual lines and failover: production never isolated.

The WAN is no longer bought in circuits but in intelligence: the policies we write, on your flows.