A practical guide to transport, policy, resilience, security, and deployment design
UNDERLAY provides the paths. OVERLAY applies the intelligence.
The underlay is essentially the network pipe — the roads that connect branches, data centers, cloud environments, and the internet. It is the physical or carrier-provided network over which traffic travels. Typical underlay services include MPLS, dedicated internet access (DIA), business broadband, fiber, 4G, 5G, and satellite.
A business might use dedicated fiber as its primary connection, broadband for additional capacity, and 5G as a backup when a wired circuit fails. All of these connections belong to the underlay. The underlay does not need to understand the business purpose of every packet; it provides reachability and exposes path conditions that the SD-WAN platform can measure and use.
The performance of the underlying transport layer determines several fundamental characteristics of the WAN:
An SD-WAN overlay cannot create bandwidth that does not exist. It can, however, use available resources more intelligently. When every link is overloaded, SD-WAN may steer critical traffic toward the least-affected path, but it cannot build a new circuit or improve weak cellular coverage. A strong overlay therefore still depends on a well-designed underlay.
A smart WAN does not treat every connection equally because each transport type has different strengths, limitations, costs, and performance characteristics.
| Transport | Typical Characteristics and Role |
|---|---|
| MPLS | Predictable private transport that may include strong service levels. It can be expensive and slower to provision. SD-WAN can retain MPLS for selected high-priority or private applications. |
| Dedicated Internet Access (DIA) | Business-grade internet that may include committed bandwidth and performance commitments. It is well suited to cloud applications, SaaS, and secure site connectivity. |
| Business Broadband | Cost-effective and often high-bandwidth, but performance may vary because infrastructure is commonly shared. Policies should use measured performance, not only advertised speed. |
| 4G and 5G | Useful for rapid deployment, temporary sites, and failover. Performance may fluctuate with coverage, signal strength, data limits, and congestion. |
| Satellite | Useful where other options are unavailable. SD-WAN policy must account for its specific latency, weather, and capacity characteristics. |
If the underlay is the highway system, the overlay is the intelligent fleet that selects routes according to business priorities. The SD-WAN overlay is the software layer that manages how the available underlay paths are used. It creates logical tunnels over physical connections and allows multiple transport services to be governed through a common policy model.
The overlay typically provides:
Consider a branch office with three underlay links:
| Underlay Link | Typical Role |
|---|---|
| Dedicated fiber | Primary business connectivity |
| Business broadband | Cloud access and general internet traffic |
| 5G | Backup connectivity and rapid recovery |
When a new traffic flow reaches the SD-WAN edge, the overlay evaluates questions such as:
The overlay then applies the relevant policy. A VoIP call may use dedicated fiber because it currently offers the lowest jitter. Finance traffic may prefer fiber and fail over to broadband if the primary link becomes unavailable or falls below the required quality threshold. Approved SaaS traffic may use direct internet access over broadband, while guest traffic is routed separately and isolated from corporate segments.
A common network problem is not a total outage but a brownout. During a brownout, a link remains technically up and may still respond to basic probes, yet high packet loss, unstable latency, or excessive jitter causes applications to perform poorly. Traditional failover methods may miss this condition because the interface itself has not gone down.
SD-WAN platforms use active probes and health checks to measure the real-time quality of each path. These measurements are compared with thresholds defined for different application classes. If a path no longer satisfies the required profile — for example, latency becomes too high for voice — the overlay can move the application to a better path even though the original circuit remains available.
| Feature | Underlay | Overlay |
|---|---|---|
| Main purpose | Provides transport and IP reachability | Controls how business traffic uses the available transport |
| Common elements | MPLS, DIA, broadband, fiber, cellular, satellite | Logical tunnels, policies, application rules, and segments |
| Ownership | Carrier, ISP, or enterprise transport team | SD-WAN platform and enterprise policy |
| Capacity | Determined by purchased services and network conditions | Prioritizes and allocates existing capacity |
| Path quality | Experiences latency, jitter, packet loss, and congestion | Measures performance and responds through policy |
| Traffic decisions | Uses provider routing and transport mechanisms | Adds centralized, application-aware path selection |
| Security | Depends on the service and local controls | Can add encrypted tunnels, segmentation, and consistent policy |
| Failure response | May rely on interface state or routing convergence | Can react to application-specific SLA violations |
| Flexibility | Limited by services available at each site | Uses different transport combinations under one policy model |
| Visibility | Often divided across providers and individual devices | Can provide a consolidated operational view |
In simple terms, the underlay provides the roads and the overlay makes their use intelligent. By measuring and dynamically managing transport resources, SD-WAN can create a more responsive, resilient, and cost-effective WAN within the limits of the available network.
Consider an organization with a head office, a data center, and 75 branch offices. Each branch uses a primary broadband circuit, a secondary internet circuit, and a cellular backup. Employees depend on a cloud CRM, a centrally hosted ERP system, voice and video conferencing, collaboration tools, large file transfers, and guest internet access.
The underlay provides the available paths. The overlay converts those paths into application-specific behavior.
| Traffic Category | Example Overlay Policy |
|---|---|
| CRM and ERP | Assign high priority and use the most stable qualifying path. Fail over when the selected path no longer meets the required quality profile. |
| Voice and video | Select a path that satisfies the configured latency, jitter, and packet-loss thresholds. |
| Cloud applications | Use approved direct internet access to avoid unnecessary data-center backhaul. |
| Guest Wi-Fi | Use a separate internet route and keep traffic isolated from corporate segments. |
| Large file transfers | Use a high-capacity transport while maintaining lower priority than interactive business traffic. |
| Cellular backup | Carry designated critical applications during a wired outage and limit nonessential traffic to control data consumption. |
This is the practical difference between simply owning three, four, or five circuits and operating an intelligent WAN. Multiple circuits create options; the overlay converts those options into controlled business outcomes.
SD-WAN introduces decision-making, but it does not remove the physical constraints of networking. The overlay cannot compensate for:
Even when services come from different providers, they may still enter the building through the same physical duct or depend on the same upstream infrastructure. Diversity at one point in the network does not guarantee diversity across the entire path.
The overlay enables more effective choices within the environment it is given. Policy alone cannot make a physically weak or poorly designed underlay resilient.
An underlay can be public or private. MPLS may be provisioned as a private service, while broadband and cellular traffic may traverse shared provider infrastructure.
The overlay may establish encrypted tunnels between authenticated edge devices. Platform-dependent security capabilities can include:
Encryption is important, but it is only one part of a broader Zero Trust or SASE architecture. A wider design may also include identity authentication, endpoint posture checks, least-privilege access, threat prevention, DNS security, and protected web browsing.
MPLS, DIA, broadband, and 5G differ in capacity, latency, cost, and reliability. Policy should reflect those differences.
Thresholds that are too strict can cause unnecessary path changes. Thresholds that are too loose can leave critical applications on degraded links.
Providers may share a duct, exchange, pole, or upstream route. Validate both physical and logical diversity.
A high download rate does not guarantee sufficient upstream capacity for meetings, backups, or site-to-site applications.
The impact of a path change depends on application behavior, NAT state, tunnel architecture, and the traffic-steering method. Some sessions may need to reconnect.
Prioritization can protect critical traffic during short congestion periods, but it cannot replace bandwidth and capacity planning.
Not necessarily. SD-WAN can reduce dependence on MPLS without requiring its complete removal. In a hybrid design, MPLS may continue to support selected private or critical applications, DIA may serve public cloud and SaaS traffic, broadband may provide additional capacity, and 5G may provide backup connectivity.
The decision to retain, reduce, or replace MPLS depends on application requirements, location, transport availability, compliance, risk tolerance, and total cost. SD-WAN changes the design choice: instead of forcing all traffic over one service, the organization can select the most appropriate transport for each application.
Making a WAN intelligent requires more than simply adding circuits.
The underlay provides capacity, availability, and physical resilience at each site. The overlay provides intelligence by continuously monitoring paths, identifying applications, enforcing policy, and adapting to changing network conditions.
A successful SD-WAN deployment designs both layers together. Reliable transport is underused without intelligent policy, while intelligent policy has too little to work with when the transport is weak or poorly designed.