SD-WAN Pilot Project for FMCG Industry
MAJOR ISSUES
Client’s existing WAN infrastructure at the Shanthiniketan office was outdated and presented significant operational limitations:
- Static Subnet Mapping: Specific subnets were permanently assigned to a single P2P link, limiting load balancing and optimization.
- Underutilized Bandwidth: No dynamic load balancing meant one 200 Mbps link could be overutilized while the other remained idle.
- No Local Internet Breakout: All traffic was routed via a centralized internet breakout at the datacenter, overloading P2P links and increasing latency.
- No Application-Aware Routing: Traditional link load balancers could not perform intelligent routing based on real-time application needs or user experience.
- Complex Hardware Requirements: Existing solutions required additional routers/firewalls and lacked support for overlay tunneling for real-time and mission-critical apps.
IMPACT
The SD-WAN transformation had a significant positive impact on Britannia’s network performance, user experience, and operational efficiency:
- Improved Bandwidth Utilization: Dynamic load balancing across all WAN links maximized throughput and prevented bottlenecks.
- Enhanced Application Performance: Application-aware routing ensured priority handling of mission-critical traffic.
- Reduced Latency & Increased Redundancy: Local internet breakout reduced
dependence on DC for all traffic, lowering latency and improving user access speeds. - Consolidated Infrastructure: Eliminated the need for additional hardware like routers and load balancers, reducing management complexity.
- Business Continuity: SD-WAN overlays and IPSec tunnels enabled resilient, always-on connectivity between office, DC, and public cloud environments
HIGHLIGHTS
Legacy Architecture:
- Dual 200 Mbps P2P links without intelligent routing.
- Static subnet-to-link mapping without failover or optimization.
- No support for application-level decisions or load distribution.
Proposed SD-WAN Solution:
- IPSec-based encrypted tunnels between on-prem and public data centers.
- Management Plane: HTTPS web sockets over TLS.
- Data Plane: End-to-end IPSec connectivity with EdgeConnect Cloud.
- Local internet breakout via ZIA Cloud for internet-bound traffic.
- Dynamic, application-aware path selection and failover.
Modern Architecture Benefits:
- Packet-based tunneling for real-time and critical applications.
- Unified architecture with centralized management and monitoring.
- Enhanced end-user experience without additional appliance layers.
KEY STRATEGIES
- Transition to SD-WAN with EdgeConnect: Implemented an overlay architecture that enables real-time tunnel formation, smart routing, and entralized policy
- Redundant Link Utilization: Introduced intelligent bandwidth sharing across all available links with automatic failover and prioritization.
- Cloud-First Connectivity: Enabled direct internet access for cloud-based apps via ZIA Cloud, cutting down on dependency on the centralized DC.
- Security Built-in with IPSec: Secured all data flows between locations and to the cloud with native end-to-end encryption.
- Streamlined Operations: Simplified the network topology by eliminating multiple hardware appliances and providing a software-defined alternative.