Guide · rw/sd-wan

SD-WAN and network transformation.

Most enterprise networks were designed for a world where the applications lived in your datacenter and the people lived in your buildings. Neither is true anymore. This guide covers how we take organisations from an MPLS-shaped estate to a software-defined, identity-aware network, and how to do it without a weekend that ends in a rollback.

CiscoCloudflareCheckpointzScalerAzureEquinixMPLSZero trust
01

Discover

Map real traffic, applications, cloud footprints and the sites that actually matter.

02

Design

Choose transport, edge security, datacenter footprint and migration waves based on facts.

03

Migrate

Run hybrid for months, site by site, with rollback plans and on-site readiness.

04

Operate

Monitor application performance, review policy quarterly and prevent drift.

Start with traffic, not with vendors

Before anyone talks about appliances, we map where traffic actually goes: which applications are in Azure, which sit in a colocation cage at Equinix, which SaaS platforms carry the business day to day, and which legacy systems still expect a private path. That map decides the design. Choosing a vendor first is how organisations end up paying for capability they never use.

The SD-WAN layer

SD-WAN gives you cheap, diverse transport with policy on top: broadband, fibre and LTE bonded per site, with application-aware steering so voice and trading traffic take the good path and backups take what is left. The value is not the cost saving on circuits, it is that you can change policy centrally in minutes instead of raising a change request per branch.

We design with Cisco and equivalent platforms, and we build the underlay with the same rigour: redundant last miles from different carriers, sane failover timers, and monitoring that tells you when a path degraded rather than when it died.

MPLS branch cost100%
SD-WAN transport cost55%
Policy change time30%
Mean time to detect path issues25%

Security moves to the edge

Once traffic leaves the branch directly for the internet, the old central firewall stops seeing it. That is where zScaler-style secure access and Checkpoint or Cloudflare edge enforcement come in: inspection, DNS control and zero-trust access applied per user and per device instead of per office. Identity becomes the perimeter, and the network only has to be fast and reliable.

Datacenter consolidation runs alongside

Network transformation without datacenter work is half a project. We usually find three or four racks of workloads that should be in a public cloud, one or two that must stay physical for latency or licensing reasons, and a long tail nobody owns. Consolidating into a smaller, well-connected footprint at a carrier-neutral facility makes every later decision cheaper.

Migrating without downtime

We run migrations site by site, starting with locations where a bad hour is survivable and ending with the ones that are not. Each wave has a pre-flight checklist, a defined rollback, and a person on site or on call who knows the building. Hybrid running, MPLS and SD-WAN live together, is normal for months and should be planned for, not treated as failure.

Operating the result

After cutover the work becomes observability and discipline: end-to-end application performance, per-site health, policy change review and quarterly design revisits as the application estate keeps moving. A network transformation that nobody maintains drifts back to its old shape within two years.

Platforms and partners we work with
Network and edge
CiscoCisco MerakiFortinetJuniperVMware VeloCloud
Security and zero trust
zScalerCheck PointCloudflarePalo Alto NetworksMicrosoft Entra ID
Cloud and datacenter
Microsoft AzureAWSEquinixInterxionNTT
Carriers and observability
ColtOrange BusinessThousandEyesDatadogGrafana

Reference architecture, site by site

A branch gets two independent transports from different carriers, usually fibre plus a cable or 5G backup, terminated on a redundant pair of Cisco or Fortinet edges. Application-aware policy steers voice, ERP and trading flows over the healthiest path and pushes backups and updates to the cheaper one. Internet-bound traffic breaks out locally and is inspected by zScaler or Cloudflare before it ever reaches a datacenter.

A regional hub sits in a carrier-neutral facility such as Equinix, holding the private interconnects into Azure and AWS, the remaining physical workloads, and the shared services that cannot live in a branch. Everything else is policy, not cabling. That is the difference between a network you configure and a network you operate.

Weeks 1-4

Discovery and truth

Traffic capture per site, application dependency mapping, contract and circuit inventory, and a cost baseline nobody can argue with.

Weeks 5-10

Design and pilot

Reference design signed off, hardware staged, and two pilot sites migrated: one simple, one difficult on purpose.

Months 3-8

Wave migration

Six to twelve sites per wave, each with a pre-flight checklist, a rollback and a named owner on site.

Months 9-12

Security and consolidation

Zero-trust access rolled out per user group, legacy firewall estate retired, datacenter footprint reduced and reconnected.

Ongoing

Operate and review

Quarterly policy review, application performance reporting and a design revisit whenever the cloud estate shifts.

A network transformation is not finished when the last site cuts over. It is finished when nobody in the business notices the network any more.
Redwind network practice
Key takeaways
  1. 01Map real traffic before you shortlist vendors. The application estate decides the design, not the datasheet.
  2. 02Treat SD-WAN, zero trust and datacenter consolidation as one program with one owner and one budget.
  3. 03Plan for months of hybrid running. MPLS and SD-WAN living side by side is a phase, not a failure.
  4. 04Move enforcement to identity. Once branches break out locally, the central firewall stops being the perimeter.
  5. 05Budget for operations. Without quarterly policy review, the design drifts back within two years.
Frequently asked
How long does a typical SD-WAN migration take?

For a fifty-site organisation, roughly nine to twelve months from discovery to the last cutover, with the first pilot live inside ten weeks. The pace is set by site readiness and carrier delivery, not by the technology.

Do we have to drop MPLS completely?

No. Many clients keep a small MPLS or dedicated-line footprint for a handful of latency-critical or regulated locations, and run everything else over broadband and 5G with policy steering on top.

Is zero trust a separate project?

It should not be. The moment branch traffic breaks out locally, identity-based access becomes the control plane. We roll it out per user group during the same waves as the network migration.

What does this cost compared with our current estate?

Transport costs typically drop by a third to a half, but the real return is operational: policy changes in minutes instead of weeks, and far fewer hours spent troubleshooting per-branch incidents.

Redwind's operating principle

We treat the network as a system that carries applications, not as a collection of boxes and circuits. That lens is what lets us run network, security and datacenter work as one coherent program instead of three disconnected projects.

See our enterprise infrastructure work · Start a project