Connectivity

What Is SD-WAN and How Does It Work?

SD-WAN (Software-Defined Wide Area Network) is a technology that manages multiple internet connections from a central software platform, intelligently routing traffic across the best available path. This plain-English guide explains what SD-WAN is, how it works, what it costs and whether it is the right choice for your business.

NH

Nathan Hill-Haimes

Technical Director

9 min read·Mar 2026

What is an SD-WAN in plain English?

SD-WAN stands for Software-Defined Wide Area Network. It manages the wide area network — the connections linking your offices, cloud apps and remote staff — using software on cloud-hosted controllers instead of hardware configured box-by-box at each site. The routing brain lives centrally, not in every router.

In a traditional WAN, every router is configured independently. Changing how traffic flows means logging into individual devices at each location and editing them by hand. With SD-WAN, the routing logic is defined once in software and pushed to every site automatically. Add a policy, change a rule or open a new office, and the change propagates everywhere through the central platform.

SD-WAN also adds intelligence ordinary routers lack. Instead of forcing traffic down a fixed path, it measures the live performance of every available connection — latency, packet loss and jitter — and sends each traffic type down whichever path is performing best right now. A video call that needs low latency takes a different route than a backup transfer that only needs bulk bandwidth. This is connectivity managed as a security-first system, which is why it sits alongside our business leased lines work rather than separate from it.

How does SD-WAN work? The key components

SD-WAN has three working parts: an edge device at each site, a central controller in the cloud, and transport-independent links underneath. The edge device terminates your circuits and enforces policy; the controller defines that policy once and distributes it everywhere; the underlying connections can be any mix of leased line, fibre or mobile.

Customer Premises Equipment (CPE)

At each location, an SD-WAN edge device sits between your local network and your WAN connections. It terminates your circuits (leased line, FTTP, 4G/5G), monitors their performance continuously, and forwards traffic according to the policies set centrally. It is the local enforcement point for decisions made in the controller.

SD-WAN controller and orchestrator

The controller is the central management plane, usually hosted in the cloud by the platform vendor. It is where traffic policies, routing rules, QoS priorities and security settings are defined. Changes made here reach every device across every site automatically, and a web dashboard shows the live status of each connection — the kind of single-pane visibility that makes multi-site connectivity manageable instead of fragmented.

Transport-independent connectivity

SD-WAN is transport-independent: it works across any combination of WAN links — leased lines, FTTP, FTTC broadband, 4G, 5G or MPLS. The edge device treats every link as a candidate path and chooses the best one per traffic type from live performance data. UK full-fibre availability has expanded rapidly under the Government's Project Gigabit programme, giving most businesses far more diverse, affordable circuits to feed into an SD-WAN than a decade ago.

What problems does SD-WAN actually solve?

SD-WAN earns its keep on four fronts: it simplifies managing many sites, it fails over intelligently before a circuit dies, it routes by application, and it lets you cut or supplement expensive MPLS. Each maps to a concrete cost or reliability pain that multi-site businesses feel every week.

Multi-site network management complexity

Managing individual routers at many sites is operationally expensive. SD-WAN centralises configuration so one administrator runs the WAN for ten sites from a single dashboard. Zero-touch provisioning lets a new site go live by shipping a pre-configured device that calls home and self-configures on first boot — no on-site engineer required.

Reliability and proactive failover

Traditional routers fail over only when a circuit goes fully down. SD-WAN watches every circuit continuously and detects degradation — rising packet loss or latency — before a link dies, rerouting sensitive traffic early. For a VoIP call, that means the call rides through a degrading connection instead of dropping, which is why it pairs naturally with resilient multi-site VoIP.

Application-aware routing

SD-WAN identifies specific applications in the traffic flow — Microsoft 365, Salesforce, Zoom, general browsing — and routes each by its needs. A live video call gets the lowest-latency path; a cloud backup gets the cheapest path; Microsoft 365 can break out directly to the internet at each site rather than backhauling through a central data centre, cutting latency for cloud apps.

Replacing or supplementing MPLS

Historically, multi-site businesses used MPLS circuits to connect offices — a private, prioritised network technology that worked well but carried a heavy cost premium. SD-WAN replicates most MPLS benefits using encrypted tunnels across cheaper public internet, and adds application awareness and multi-path routing that MPLS never had. Ofcom's business connectivity market data tracks the wider shift from legacy private circuits to fibre-based services that makes this migration viable for SMEs.

How does SD-WAN compare to a traditional WAN router?

The core difference is centralised, performance-aware software control versus per-device manual configuration. SD-WAN fails over proactively, routes by application, and deploys to new sites with zero-touch provisioning. A traditional router is cheaper to buy outright but costs far more to operate at scale and reacts only after a link has already failed.

AspectSD-WANTraditional WAN router
ConfigurationCentralised, policy-driven, cloud-managedPer-device, manual, CLI or web interface
FailoverSub-second, proactive, based on continuous monitoringReactive — triggered only on link-down
Application routingApplication-aware, real-time per-app path selectionStatic routes, no application visibility
Multi-site deploymentZero-touch provisioning, consistent policy everywhereManual per-site config, inconsistent enforcement
Cost modelHardware plus monthly software subscriptionHardware-only, no ongoing software fee

Is SD-WAN right for your business?

SD-WAN makes sense once complexity or cloud reliance outgrows a single router. It becomes compelling from roughly three connected locations upward, or sooner if cloud apps and voice quality are business-critical. For a single-site business on one circuit, it adds cost and complexity that a good managed firewall with solid QoS handles better.

SD-WAN typically fits businesses that meet one or more of these:

  • Multiple offices — the centralised-management benefit grows with every site you add
  • Heavy cloud usage — application-aware routing for Microsoft 365, CRM and video delivers measurable gains
  • Significant MPLS spend — internet-based SD-WAN can materially cut equivalent MPLS capacity costs
  • VoIP quality problems — proactive failover and QoS are well-suited to protecting voice
  • Fragmented WAN — multiple site-level routers with no central visibility

If you also need diverse circuits to feed the SD-WAN, pairing it with backup connectivity gives you the second path that makes intelligent failover worthwhile.

SD-WAN options for UK businesses

The main SD-WAN platforms used by UK SMEs differ mostly on how much security and management they bundle. Cisco Meraki and Fortinet dominate the SME end; fully managed services such as Cato suit businesses with no in-house network team. The right choice depends on your existing kit and how much you want to run yourself.

  • Cisco Meraki MX — cloud-managed, strong fit if you already run Meraki switching and wireless.
  • Fortinet Secure SD-WAN — security-first, combining SD-WAN with next-generation firewall in one device.
  • Palo Alto Prisma SD-WAN — enterprise-grade with strong application identification, common in larger SME deployments.
  • Aryaka / Cato Networks — fully managed SD-WAN-as-a-service where the provider runs the hardware, software and underlying network.

AMVIA designs and manages SD-WAN deployments for UK businesses, typically working with Cisco Meraki or Fortinet depending on your existing infrastructure and requirements. Because we run resilient business VoIP on the same networks, voice protection is designed in from day one, not bolted on.

What does SD-WAN cost for a UK SME?

SD-WAN pricing has two parts: hardware (a CPE at each site) and a software subscription (the controller and management platform). Your existing circuits stay — SD-WAN manages them, it does not replace them. As indicative 2026 figures, expect hardware and a monthly per-site subscription on top of your current connectivity spend.

  • Hardware: approximately £400–£1,500 per site (typical UK 2026 range), depending on throughput and vendor
  • Software subscription: approximately £50–£150 per site per month (market rates as of 2026), depending on platform and feature set
  • WAN circuits: your existing leased line, FTTP or broadband costs — unchanged

For a three-site business migrating from MPLS, total SD-WAN cost over three years is often materially lower than the equivalent MPLS circuits while giving better performance visibility and easier management — a saving frequently cited in the 30–50% range (typical UK 2026 range). The exact figure depends entirely on your current MPLS contract and circuit mix, so treat any headline percentage as a starting point for your own modelling.

Is SD-WAN the Right Choice for Your Business?

AMVIA compares SD-WAN, leased lines and managed broadband options for your specific sites and requirements. We make the recommendation that is right for your situation, not the one with the best margin.

Frequently Asked Questions