You are on page 1of 7

SD-WAN – architecture, functions and benefits

P. Segeč*, M. Moravčík*, J. Uramová*, J. Papán*, O. Yeremenko**


* Faculty of Management Science and Informatics, University of Zilina, Univerzitna 8215/1, 010 26 Zilina
** Kharkiv National University of Radio Electronics, Ukraine, Kharkiv
* e-mail: {pavel.segec, marek.moravcik, jana.uramova, jozef.papan}@fri.uniza.sk
** e-mail: oleksandra.yeremenko.ua@ieee.org

Abstract—SD-WAN is currently considered as a technology networking, where it is expected, that network will
that has the potential to revolutionize the use of WAN accommodate needs of applications, services and
services. It supports a new concept known as Application- customers [2]. This concept allows to SD-WAN service to
driven networking, where the network is expected to meet replace traditional WAN services provided over costly
the needs of applications, services and customers. In short, MPLS (MultiProtocol Label Switching) VPN (Virtual
SD-WAN is a centralized management of WAN networks, Private Networks) technology and to reduce costs on
usually with a close connection to Cloud computing and network administration with application of centralized and
security. This way, customers can easily manage their automated administration elements. These arguments may
networks regardless of the connectivity provider. SD-WAN be more suitable at enterprise deployment, SD-WAN
is currently one of the most current topics with a real service can be, on the other hand, operated over more
impact on CC services and WAN environments. SD-WAN different WAN connections, including affordable public
influences thinking about how we have used network broadband connections (Figure 1). SD-WAN offers to this
services so far. More importantly, it has great potential to segment of customers access to newer and better services
change the way we use communication services in the resulting from SD-WAN technology features. And it is
future. There are several industries that are interesting in just for a fraction of the cost of the MPLS VPN services
terms of SD-WAN deployment. Based on our analyzes, we offered. SD-WAN service with balanced offer of
can include the education sector among them. interesting features and offered over broadband access has
potential to address customer segment, for which was
Keywords—SD-WAN, architecture, entities, functions,
private MPLS VPN service unaffordable or otherwise
benefits.
unavailable (unavailability of access technology, etc.) [3].
Based on the knowledge of the education sector and the
I. INTRODUCTION availability of information on various infrastructure
The direction of today’s digital world can be described projects, we believe that the education sector could be an
by term „cloud-based everything“. From application to interesting customer of managed SD-WAN services.
network communication, Cloud Computing (CC) pushes However, not individually, but rather in the form of
out traditional solutions at a fast pace. Of particular centrally solved informatization infrastructure projects
interest is how CC transforms the WAN environment with under the auspices of the Ministry of Education, Science,
the emergence of an approach known as Software-Defined Research and Sports of the Slovak Republic, which would
WAN (SD-WAN). SD-WAN is directly characterized by help primary and secondary schools solve network
the application of so-called "Cloud-centric" access to the management problems and increased network security
network area, making strong use of the principles defined requirements. SD-WAN can offer a centralized and easy-
for Software Defined Networks (SDN). SD-WAN is today to-use way to manage and install communication services
one of the most current topics with a real impact on CC in schools with virtualization support, security assurance
and WAN services. And thus also their users, to which we and security policy enforcement in this environment.
can currently include the public sector and education [1]. However, SD-WAN can also be interesting for
SD-WAN is nowadays considered as technology that university environments. For example, the well-known
has potential to revolutionize WAN service usage. It university and higher education sector in Slovakia uses
support new concept known as Application-driven a distributed telepresence infrastructure called NTI
SD-WAN
controller

MPLS

Broadband
MPLS WAN access

PE PE SD-WAN CPE
CE CE SD-WAN CPE
3G/4G

Traditional WAN SD-WAN = More network types + controller


Figure 1 WAN vs. SD-WAN
(national telepresence infrastructure), Office 365 is production world), called the controller (intelligent logic
deployed in terms of SaaS services and is characterized by of SDN), or also the Network Operating System (NOS).
high mobility and teleworker activities of its staff and Physical network devices are in SDN networks used only
students with access to internal university services. Here, for their functions connected with data forwarding
SD-WAN can offer greater comfort and stability of the (switching / forwarding). This approach allows the
offered communication services with the integration and abstraction of control from the physical network
use of CC services while guaranteeing a high level of infrastructure, often represented as a virtual switch, and
security. allows central programming (automation) of network
Knowledge of SD-WAN technology is such a current behavior or policies or services in one place (often used in
trend with a real impact on thinking, as we have used IT style by usage of programming interfaces and tools).
network services so far. More importantly, however, it has The simplified SDN architecture contains three logically
great potential to change the way we use communication separated planes [5] [6] (Figure 2):
services in the future. In this article, we will therefore • Data plane / plane of network infrastructure. It
focus on the introduction of SD-WAN technology, its consists of hardware or software network devices
architecture, entities and offered functions. (data forwarding elements, such as routers,
The paper is organized as follows. After the switches, firewalls, etc.) similar to traditional IP
introduction provided in chapter I. Chapter II introduces (Internet Protocol) networks, but with excluded
technologies related to SD-WAN, the SDN and NFV control functions.
(Network function virtualization). Chapter III is devoted • Control plane / plane of SDN controller. A key
and provides a description of the SD-WAN architecture. component used as software entity is called
Next two chapters provide deeper technical related controller (or NOS). It combines the control and
descriptions. Chapter IV describes SD-WAN APIs management of network functions. NOS
interfaces, and chapter V introduces the SD-WAN (controller) via API (Application Programming
equipment and entities. In the following two chapters, we Interface) provides an abstraction of network
introduce the necessary features of SD-WAN (chapter functions and data plane services (e.g. network
VI), and then we identify what benefits the SD-WAN can status, topological information, configuration and
offer (chapter VII). Finally, chapter VIII concludes the reconfiguration of devices, management, etc.).
paper. • Application plane / plane of network SDN
applications (sometimes called as orchestration
II. RELATED TECHNOLOGIES plane). It uses the functions and services offered by
SD-WAN technology uses some SDN approaches that the control plane to create the logic of network
are applied to WAN networks, and the generic model is SDN applications, which is translated by the
very similar. The second key technology that is important controller into a specific configuration of the
to know about understanding the SD-WAN concept is network device and installed on the network
Network Functions Virtualization (NFV). SD-WAN is device.
referred to in the available literature as the combined Important in the SDN concept are separated planes
usage of the approaches introduced in SDN and NFV. interconnected through program APIs (open or
proprietary). There is a Northbound API between the
A. Introduction to Software Defined Networks
One of the breakthrough approaches of the last period
in the field of networking is the considered emergence of
the so-called Software Defined Networking (SDN). SDN
as a concept is focused on solution of one of the
fundamental problems of current networking. This
problem is complexity growing in many aspects [4].
Complexity of IP networks results from their design
principles and from their building and administering as
natively distributed system (diverse of integrating devices,
protocols, administration policies and so on), which is
vertically integrated in form of common and Figure 2 SDN from point of view (a) planes, (b) layers (c) and
system design [4] [23]
interconnected control and data plane implemented in
specific operating system (OS) of network device (for
example Cisco IOS, Juniper JunOS, etc.). Changes due to controller and the application plane. The Northbound API
the adaptation or introduction of new services to this type is used to programmatically connect the controller to the
of infrastructure are usually very complex and difficult application plane, where all network SDN applications are
(for example introducing of new service or customer located. This type of interface allows administrators to
requires set of separated actions throughout whole take advantage of high-level programmability and high-
infrastructure). level network automation. An example for the application
SDN thus creates a new approach to the design and of the northbound interface can be the use of the REST
operation of network infrastructure, where the network API, which can then be integrated with modern
control plane (control logic) is separated from the data automation tools such as. Puppet, Chef, Ansible, and so on
level (device forwarding functions). The control functions [7]. Through the Northbound API, network applications
in the SDN are extracted from individual devices and are can influence network management, where the controller
integrated into a centralized control node (redundant in the then translates the required instructions into instructions
sent via the Southbound API to network devices (setting application of network functionalities, e.g. running in DC
up flow tables or reconfiguring devices). or in a virtualized CC (Cloud Computing) environment.
There is a Southbound API between the network The transition to software instances of network functions
infrastructure level and the controller. Through this API, also offers the possibility of flexibility through
the controller controls the forwarding functions of the programmable dynamic resource management (change,
network infrastructure elements, or, reversely, the network addition, deletion of VNF), e.g. via SDN. However, SDN
elements make their functions or required information is not a mandatory part of VNF, it is a suitably
available to the control plane. Through this interface, the complementary technology to VNF.
SDN controller can be "hidden" from the SDN application ETSI [9] therefore considers the main objectives of
specific network devices from different manufacturers and NFVs to be the possibility to innovate existing services by
the specifics of their configuration. A typical Southbound deploying NFV network functions (including self-service)
API is the OpenFlow open protocol, standardized by the through software development. It allows the use of
Open Networking Foundation (ONF) [4]. However, automation and orchestration through software (e.g.
OpenFlow is not the only standard for the southbound controller). Overall, the deployment of NFV is expected to
interface in SDN, and alternative open (NetConf, LISP, reduce costs (Opex / Capex), which can bring benefits in
XMPP, BGP, MPLS-TP, OVSDB) and proprietary (Cisco the form of reduced electricity consumption, reduced
OpFlex) solutions are currently available (or under overall equipment costs and increased time to market
development). process.
According to [8], there are four basic building blocks of
SDN: III. SD-WAN ARCHITECTURE
• Dividing functions to layers: data/forwarding SD-WAN, as mentioned before, is currently one of the
plane, control plane, management plane most actual topics because it connects SDN, NFV, CC and
• Simplified devices and central controlling: WAN services (e.g. broadband Internet service) [1]. SD-
Controller distributed configuration to all other WAN architecture (Figure 3), similar as SDN architecture
devices consist of three architectural planes. They are
infrastructure, or data plane, control plane and
• Network automation and virtualization orchestration plane.
• Openness

A. Data plane
B. Network function virtualization The data plane is able to establish connections via both
According to European Telecommunications Standards private and public IP / WAN infrastructures. It is designed
Institute (ETSI) [9], Network Functions Virtualization to simplify communication between geographically
(NFV) is technology that focuses to usage of standard IT separated sites, as well as with cloud applications and
virtualization technologies. NFV can replace current services. For this purpose, SD-WAN creates its own
physical network devices (servers, switches, routers, software-managed logical infrastructure over the existing
gateways, firewalls, etc.) by software network devices (or physical infrastructure. This type of network is called
functions) referred to as Virtual Network Function (VNF). Overlay, the existing physical infrastructure is called
The purpose of NFV is to save resources by using Underlay. While SD-WAN overlay is usually uniform and
generic and, therefore, cost-effective hardware for the consistent, physical infrastructure of underlay WAN

Control plane
Bussiness Service
Orchestrator Virtualization
Policy Insertion
Orchestration
of services and
network Other (Templates,
App. Perfor. Analytics, Reports, ...)
Orchestrator Dynamic multi- Security
SD-WAN

path opti. Monitoring


in CC Northbound API

Control plane

East-West
Overlay
Controller API
control Controller v CC
Southbound API

Infrastructure

Overlay CPE/Edge SD-WAN Gateway CPE in CC SD-WAN Gateway in CC


Underlay

SO/HO Mobile
Underlay Branch HQ Data center
user

Figure 3 SD-WAN architecture


networks is usually heterogenous and fragmented. Some from a centralized management level after authentication
solutions may use only one uplink (i.e. MPLS). Other [2]. This form of automation eliminates the need for
solutions can use only local Internet connection with one qualified staff at each branch.
uplink, or use combinations of lines and technologies The management level itself can be located at on-
(DSL, 4G/5G etc.) or even their combinations with leased premises IT infrastructure or in the cloud. The main entity
lines or other private WAN solutions. at this level is an entity called an orchestrator, while some
Overlay networks can logically create several types of manufacturers also have an entity referred to as a
links (hub & spoke, full mesh, partial mesh, point-to- manager. The orchestrator is a component focused on the
point, controller-behind-branch, branch-behind-branch, integration and orchestration of the entire SD-WAN
etc.). Network overlay features include support for VPN solution, while analyzes show that these are strongly
networks, either VPN on the second (L2 VPN) or third proprietary solutions. Here, each manufacturer has its own
layer (L3 VPN). From the routing, it supports IPv4 and software solution for this entity, which is also variously
IPv6 addressing, as well as multicast. Of course, there are named. The implementation can be as a standalone
security features that should be offered by all solution or as a component integrated into the controller,
manufacturers. This can be, for example, the possibility of including several sub-entities.
implementing and distributing PKI (Public Key
Infrastructure) certificates between the controller and the IV. API INTERFACES IN SD-WAN
CPE (Customer Premises Equipment) of the SD-WAN API is one of the most important communication tools
customer's devices. In terms of encryption, we can divide in SD-WAN. Using API calls, applications communicate
secure traffic into two parts, the encryption of the control with the controller or controller with CPE devices.
layer and the encryption of the data layer. In the control
layer, it is possible to encrypt the control information of A. Southbound API
the controller towards the CPE devices. We can use IPSec,
symmetric / asymmetric encryption using PKI certificates, The communication between CPE and the controller is
TLS / DTLS, etc. Data layer encryption means the also called the Southbound API. These calls are in some
encryption of customer traffic itself, where the family of cases proprietary, but the Open-Flow or REST API can
IPSec or SSL VPN protocols is mostly used. Another also be used. From a SD-WAN vendor's perspective
option is to deploy and use third-party security devices Fortinet, VeloCloud and VersaNetwork use RestAPI as
and features. the South API. Cisco Viptela (OMP over DTLS / TLS),
Nokia (OpenFlow, OVSDB and proprietary OF-TLS) and
B. Control plane Riverbed (SteelFlow) use their own protocols.
The principle of operation of SD-WAN, like SDN, B. Northbound API
separates the control plane for centralizing control logic
from the data plane. The main entity of the plane is the The Northbound API allows the controller to
controller (or several controllers), which can be located at communicate with external applications that can send
a branch, headquarters, data center, or in the cloud. This control information to the controller or obtain status data
layer is responsible for controlling the configuration of the from it. The REST API is also often used for these calls.
connected devices, while the CPE is connected to the From the point of view of the analysis of SD-WAN
controller by a secure control connection (southbound manufacturers, those manufacturers who use the open
API). Federation of controllers and clustering can be Southbound API also use the open Northbound API, i.e.
implemented using the East-West API (MP-BGP, or Fortinet, VeloCloud, VersaNetwork, SilverPeak and
custom solutions). This layer is also responsible for Riverbed. Exceptions are Cisco Viptela, which uses
optimizing the communication flow sent through the VPN NETCONF, and Nokia Nuage, which uses XMPP,
tunnel to each of the different types of services, such as RestAPI, and JSON-RPC.
branch services, data center services, and cloud services.
C. East-west API
The programming of the SD-WAN service towards the
orchestrator entity (or manager) is implemented via the The last type of API is the so-called East-West API, which
Northbound API interface, where mainly RestAPI is used. is communication between the same entities, such as
between two CPEs or two controllers. For most SD-WAN
C. Orchestration plane solutions, no more information could be found about the
The Orchestration Plane provides a business policy East-West API, with the exception of Cisco Viptela,
framework and addresses service security policies and which uses its own OMP protocol via DTLS / TLS for
corporate governance strategies [10]. controller communication, and Nokia Nuage, which uses
MP-BGP for federation of controllers.
The management level is a high-level abstraction for
policy enforcement (centralized and unified policy V. SD-WAN DEVICES AND ENTITIES
management), configuration management,
troubleshooting, monitoring, analytics, predictions, The following entities are usually implemented in an SD-
correlations, reporting, and notifications. Then there are WAN architecture.
service-related functions, such as creating and managing
services. Consolidation of these features creates a superior A. Customer CPE devices
management interface that can easily manage large CPE (Customer Premises Equipment) is entity of network
deployments. The concept of such deployments is known infrastructure plane, which is typically placed on
as Zero-Touch Provisioning (ZTP). In the case of ZTP, it headquarters, branch office or in Cloud environment of
is not necessary for each CPE to be individually particular SD-WAN customer. Nowadays, there are
configured, but instead it downloads its configuration mainly following types of CPE devices:
• Virtual CPE: vCPE is virtual solution of specific actively monitors the network and its parameters, it can
network function, it is, therefore, virtual instance of send error messages to the administrator when certain
VNF [11], which is being run on physical values are exceeded.
proprietary devices, uCPE devices or in fully Although the controller and orchestrator are two
virtualized environment such as CC environment separate entities, they can be controlled by dashboard,
(vCPE is then so-called cloud vCPE). which was mentioned earlier. Configuration is set on
• Universal CPE (uCPE): is an evolution of vCPE- orchestrator, it then sends instructions to controller, which
initiated NFV virtualization. uCPE is essentially a sets end devices (CPE).
white-box (or gray-box between an open (white)
and a closed (black) solution) based typically on D. Cloud gateways
the Intel x86 architecture (although other Cloud gateways are entities, mostly with multitenancy
architectures such as ARM also appear). This support, deployed in top-tier networks and cloud data
device should primarily use open standards and centers around the world that provide an extension of SD-
interfaces, and generic hardware components (cost WAN technology as close as possible to entering the
reduction) with sufficient performance. The device cloud services environment. Their role is to provide and
should allow easy deployment (ideally "zero- ensure optimized access to cloud data centers and
touch") with easy maintenance and updating. It services, as well as to the private backbone network and
should be possible to download and run one or traditional corporate branches (without SD-WAN). These
more vCPE / VNF instances on the device. We are gateways are located in Service Provider (SP) data centers
talking about routing, switching, FW / NAT / UTM around the world, close to global cloud service providers
/ IDS / IPS, voice functions (PBX, SBC, IMS), (Office365, AWS, SalesForce and many more). They
WAN optimization, management and others that provide connectivity through the best possible way to the
run on one physical device. Currently, although the cloud provider and optimize cloud traffic. SD-WAN
name may be confusing, there is no standardized gateways are usually virtual devices located on the edge of
hardware and OS solution for uCPE [16], although a data center. However, not all manufacturers offer such a
several manufacturers are trying to standardize virtual device.
them.
• Closed / proprietary CPE (CPE appliance): are VI. SD-WAN FUNCTIONS
devices, that are designed specifically as CPE Depending on the manufacturer (history, motivation),
devices, which has additional SD-WAN current SD-WAN solutions have many functions, where
functionality. These devices cannot be used on orientation between them is sometimes problematic, as
another purpose or have restricted functions of well as generalization of their functions, because the view
VNF virtualization. of SD-WAN functions differs from vendor to vendor. In
the professional literature, however, it is accepted to see
B. SD-WAN controller which functions a quality SD-WAN solution should
The controller is a standalone physical or virtual device fulfill. These criteria were developed by the ONUG (Open
that provides control of the CPE and other entities, e.g. Networking User Group) in its SD-WAN 2.0 WG
CC gateways, in SD-WAN. In many solutions, it is working group [12]. ONUG defined that the SD-WAN
available as multi-user (multi-tenant) and deployable in solution should meet the so-called top ten strategic
CC (cloud-based). In terms of deployment options, the requirements (also called ONUG TOP 10) [13] and in
controller can be deployed as a physical or virtual device addition six general features to address the openness of
directly at the customer (on-premise), or can be located in network systems.
the cloud (Amazon AWS, MS Azure, etc.), or directly at
the SD-WAN solution provider / services (provider- A. Onug top TEN
hosted). ONUG TOP 10 criteria are generally accepted by SD-
The controller is responsible for configuration, WAN vendors. SD-WAN devices are often compared
activation, management of IP addresses and policy according to ONUG TOP 10, so we can state, that these
enforcement on SD-WAN devices. It also maintains are generic functions, which are expected from SD-WAN
connections to all devices so that it can identify the solution. The criteria are as follows:
operating state of overlay tunnels across different WANs 1. Active/Active: It is the ability of the site / branch
and obtain QoS connection parameters for each tunnel to use public and private WAN networks / links
separately. (hybrid mode) operating in active / active mode for
the purpose of application in order to better use the
C. Orchestrator (manager, director) total available connection capacity.
The orchestrator in many SD-WAN solutions is a 2. CPE: Flexibility and simplicity that allows you to
multi-tenant, cloud-based, centralized management for deploy SD-WAN CPE as either a physical or
configuring and monitoring SD-WAN services in real virtual device (branch, headquarters, cloud) that
time. Its main task is to monitor the entire SD-WAN uses commodity hardware to run. It should be
infrastructure. It is possible to monitor the status of lines, possible to manage the equipment remotely.
whether in overlay or underlay network. It can actively
3. Security and business policy. Support for a secure
measure their parameters, such as QoS (delay, jitter,
hybrid WAN architecture (VPN) that enables
losses), load, or directly the status of the service /
dynamic traffic engineering over paths built over
application that uses the line. Based on this information, it
both public and private WANs and routing
compiles various statistics, graphs or reports. Because it
performed according to a defined policy. Traffic
management should consider and allow the VII. WHAT CAN SD-WAN OFFER?
selection of routes per application based on defined At present, changes in the business behavior of
application policies, network availability or companies and organizations are being strongly promoted.
respond to deteriorating conditions in the transport They have a significant impact on the way traditional
or application level. WAN services are used, and their use can now become
4. Visibility, prioritization and application suboptimal for many reasons.
management. Flow visibility, prioritization, and According to Webtorials portal (Distributed
real-time management of mission-critical and Networking Associates) [14] organizations that have used
application-based policy, security, and application ISP’s services have concerns or doubts about the
requirements. deployment and use of their WAN services. Some of the
5. High availability and resiliency. Requirement for main concerns mentioned in the analyzed sources, which
availability and resilience of the hybrid WAN are e.g. for the MPLS VPN service, include the cost,
environment against outages (CPE devices or uptime, and time required to implement new MPLS
WAN lines) while maintaining the optimal services. Concerns related to services offered over the
experience for the client or application. public Internet, in turn, include security, uptime, and
6. Interoperability on L2 and L3 ISO OSI. latency. Some of the limitations associated with mobile
Requirement on collaboration of SD-WAN CPE services include variable signal coverage, line set-up
devices with directly connected devices working latency, and security. The reasons why we as customers
on second (switched) and third (routed) layer of should opt for SD-WAN can be various. However, based
ISO OSI. on our analysis, we can categorize them into areas offered
7. Management dashboard / portal. It should be by SD-WAN [14] [15] [16] [17] [18] [19] [20] [21]:
possible to check and report the SD-WAN service • New way of marketing, which is closer to the
through the dashboard, which supports reporting software approach.
(e.g. status, performance, forecast) for the branch • Possibility to simplify WAN management, branch /
office, application or VPN tunnel. SOHO networks and optimization of application
8. Controller with open API support. Requirement administration.
for support of open access to controller functions • Reducing cost for WAN connectivity services.
(for example reading / writing logs, SIEM
(Security Information and Event Management), • Mastering of increasing virtualization service,
and so on). security functions and CC usage.
9. Zero Touch Deployment (ZTD). Support for easy • Mastering problems of increasing requirements on
installation and deployment of CPE devices broadband access and increasing volume of
remotely, requiring the ability to be deployed by transmitting data.
untrained personnel and without the need to make • Mastering of increasing pressure on security and
configuration changes to the local existing unification of its processes.
infrastructure. The device only needs to correctly
connected internal and external interfaces, where
the automatic process of initialization and Whilst SD-WAN is new technology, about which there
authentication will take place. are many myths between potential customers, according to
[21][22] there are, from customer’s point of view,
10. Valid FIPS 140-2 certificate. Valid certification following benefits, that SD-WAN offers:
based on FIPS (Federal Information Processing
Standard), security level 2. 1. Application visibility: The customer of SD-WAN
gains the ability to "see" across the entire
In addition to ONUG TOP 10 strategic requirements infrastructure and down to the level of flows of
for SD-WAN, ONUG also defines six general features for specific applications. This opens up opportunities
solving the openness of network systems: for easier identification of problems.
1. Automated device discovery, provisioning and 2. Alerts and notifications: Thanks to SD-WAN,
registration of assets for physical and virtual administrators can get end-to-end problem
devices. reporting (e.g. violation of SLA) without tracing.
2. Automated tool for configuration (no hands-on 3. Cloud proxies: SD-WAN can act as tool and
keyboards), which are equal to functions used by motivation to further CC migration, and, at the
DevOps and NetOps. same time, it offers ability to see what is going on
3. Unified controller and control protocol for physical at CC environment up to application layer.
and virtual appliances. 4. Central control of application and security
4. Baseline Policy Manager which communicates policies – higher flexibility and security: SD-
with common controller for policy enforcement. WAN offers tools to solve application and security
5. A mechanism for sharing network status and a policies and configuration/tuning of network
unified network status database that automatically behavior and setting or managing of SLA.
collects at least forwarding tables of MAC and IP 5. Production portal: Instead of using multiple
addresses. applications to manage existing WAN solutions,
6. Integrated monitoring of overlay an underlay SD-WAN offers a single environment focused on
network. providing all the features.
6. High availability and resiliency: Possibility to wan-entry-point-for-software-defined-
use robust and dynamically solved redundant everything/#3861105c46ee.
solutions from redundancy of devices, paths (also [2] MEF (Metro Ethernet Foundation), “Understanding SD-WAN
Managed Services,” 2017. [Online]. Available:
Active / Active) to application redundancy and http://www.mef.net/sd-wan/understanding-sd-wan.
performance tuning and load balancing [3] “How network operators can differentiate SD-WAN
services.” [Online]. Available:
https://searchnetworking.techtarget.com/tip/How-network-
According to [22] we can add: operators-can-differentiate-SD-WAN-services.
1. CPE and NFV: Ability to use one physical [4] D. Kreutz, F. M. V. Ramos, P. Esteves Verissimo, C. Esteve
solution at branch for more functions, originally Rothenberg, S. Azodolmolky, and S. Uhlig, “Software-
solved on separate devices. Defined Networking: A Comprehensive Survey,” Proc. IEEE,
2. Ability for flexible access solutions: The solution vol. 103, no. 1, pp. 14–76, 2015.
[5] P. Helebrandt and I. Kotuliak, “Novel SDN multi-domain
allows you to manage services across different architecture,” in ICETA 2014 - 12th IEEE International
access SPs, with simplified management of Conference on Emerging eLearning Technologies and
available bandwidth (adding and removing access Applications, Proceedings, 2015, pp. 139–143.
lines) and path selection. According to Cisco, SD- [6] ONF, “SDN architecture,” 2014. [Online]. Available:
WAN carrier Ethernet was used as the primary https://www.opennetworking.org/wp-
access technology for early implementations. content/uploads/2013/02/TR_SDN_ARCH_1.0_06062014.pdf
.
[7] “What are SDN Northbound APIs (and SDN Rest APIs)?”
VIII. CONSLUSION [Online]. Available:
SD-WAN is a very current topic, as indicated by https://www.sdxcentral.com/sdn/definitions/north-bound-
various studies (IDC, Gartner, IHS Markit, Ovum, interfaces-api/.
[8] P. Goransson and C. Black, “Software defined networks : a
Quadrant, etc.) and the scientific community has not yet comprehensive approach,” 2014, p. 325.
responded to it, as has been the case with SDN. It is not a [9] M. B. Chiosi et al., “Network Functions Virtualisation,” 2012.
topic that is its basis, but responds to the needs and trends [Online]. Available:
of user development. There is a very strong interest of the http://portal.etsi.org/NFV/NFV_White_Paper.pdf.
organization to build cost-effective solutions for secure [10] D. P. Sanjay Uppal, Steve Woo, Software-Defined WAN for
and guaranteed communication services (encrypted as Dummies, 2nd VMware., vol. 136, no. 1. John Wiley & Sons,
Inc, 2018.
well as with advanced security features), operated over the [11] P. McCabe, “Universal CPE and SD-WAN: Driving a
public Internet. At the same time, there is a significant network services revolution - Broadband Technology Report,”
trend of migration and use of virtualized and cloud 2018. [Online]. Available:
services (IaaS, PaaS, SaaS - XaaS such as storage, voice / https://www.broadbandtechreport.com/articles/2018/08/univer
video / unified communication, IT, applications, etc.). sal-cpe-and-sdwan-driving-a-network-services-
From the point of view of potential SD-WAN customers, revolution.html.
it is possible, according to our analyzes, to include [12] “Software-Defined Wide Area Networks WG | ONUG.”
[Online]. Available:
organizations that plan to use Cloud services intensively. https://www.onug.net/community/working-groups/open-sd-
Multi-branch companies and companies offering mobility wan-exchange/.
to their employees (or the use of teleworking), which have [13] “ONUG Software-Defined WAN Use Case,” 2014.
to deal with WAN connectivity, network and equipment [14] B. Jim Metzler and S. Taylor, “The 2018 Guide to WAN
management at branches / SOHO, application Architecture & Design | Applying SDN and NFV at the WAN
optimization, security and the growing complexity of this. Edge,” 2018.
Organizations and companies that record an increase in [15] J. Metzler and S. Taylor, “2018 Guide to WAN Architecture
& Design |Applying SDN and NFV at the WAN Edge.”
the use of real-time video communication and the [16] Forrester, “The Future Of The WAN Is Software-Defined.”
associated increase in communication volume and [17] SilverPeak, “Top Benefits of SD-WAN - Building a Better
connection speed requirements. All with the increase in WAN with a Complete Solution.” [Online]. Available:
security requirements. Based on these characteristics, we https://www.silver-peak.com/sd-wan/top-benefits-sd-wan.
can easily include the education sector among future users [18] Versa Networks, “The Benefits of SD-WAN with Integrated
of SD-WAN. Healthcare is a similarly identified as an Branch Security,” 2017.
[19] N. Labs, “SD-WAN COMPARATIVE REPORT Total Cost
interesting sector too. of Ownership (TCO),” 2018.
[20] “Gartner Says 8.4 Billion Connected "Things"
ACKNOWLEDGMENT Will Be in Use in 2017, Up 31 Percent From 2016.” [Online].
Available: https://www.gartner.com/en/newsroom/press-
This publication has been published with the support of releases/2017-02-07-gartner-says-8-billion-connected-things-
the Operational Program Integrated Infrastructure within will-be-in-use-in-2017-up-31-percent-from-2016.
project: “Výskum v sieti SANET a možnosti jej ďalšieho [21] Orange Business Services, “Meeting the challenge of the
využitia a rozvoja/ Research in the SANET network and digital age with SD-WAN.”
possibilities of its further use and development”, ITMS [22] “SD-WAN Implementation: Tips - Cisco and BT.” [Online].
code 313011W988, co-financed by the ERDF. Available: https://www.cisco.com/c/en/us/about/case-studies-
customer-success-stories/bt-sd-wan-video.html.
[23] F. Hu, Q. Hao, and K. Bao, “A Survey on Software-Defined
REFERENCES Network and OpenFlow: From Concept to Implementation,”
[1] J. Bloomberg, “SD-WAN: Entry Point For Software-Defined IEEE Commun. Surv. Tutorials, vol. 16, no. 4, pp. 2181–2206,
Everything.” [Online]. Available: 2014.
https://www.forbes.com/sites/jasonbloomberg/2017/03/20/sd-

You might also like