SD-WAN

SD-WAN Underlay and Overlay Explained: How Intelligent WAN Architecture Works

SD-WAN Underlay and Overlay Explained

Beyond the Circuits

A practical guide to transport, policy, resilience, security, and deployment design

UNDERLAY provides the paths. OVERLAY applies the intelligence.

Introduction

The underlay is essentially the network pipe — the roads that connect branches, data centers, cloud environments, and the internet. It is the physical or carrier-provided network over which traffic travels. Typical underlay services include MPLS, dedicated internet access (DIA), business broadband, fiber, 4G, 5G, and satellite.

A business might use dedicated fiber as its primary connection, broadband for additional capacity, and 5G as a backup when a wired circuit fails. All of these connections belong to the underlay. The underlay does not need to understand the business purpose of every packet; it provides reachability and exposes path conditions that the SD-WAN platform can measure and use.

1. Understanding the Underlay

The performance of the underlying transport layer determines several fundamental characteristics of the WAN:

  • Available speed: The amount of downstream and upstream bandwidth available.
  • Network quality: Latency, jitter, packet loss, congestion, and consistency.
  • Reliability: How often the connection is available and how quickly service is restored after a fault.
  • Cost: The recurring and installation cost of each service.
  • Geographic reach: The locations and regions that can be connected.

An SD-WAN overlay cannot create bandwidth that does not exist. It can, however, use available resources more intelligently. When every link is overloaded, SD-WAN may steer critical traffic toward the least-affected path, but it cannot build a new circuit or improve weak cellular coverage. A strong overlay therefore still depends on a well-designed underlay.

A smart WAN does not treat every connection equally because each transport type has different strengths, limitations, costs, and performance characteristics.

Transport Typical Characteristics and Role
MPLS Predictable private transport that may include strong service levels. It can be expensive and slower to provision. SD-WAN can retain MPLS for selected high-priority or private applications.
Dedicated Internet Access (DIA) Business-grade internet that may include committed bandwidth and performance commitments. It is well suited to cloud applications, SaaS, and secure site connectivity.
Business Broadband Cost-effective and often high-bandwidth, but performance may vary because infrastructure is commonly shared. Policies should use measured performance, not only advertised speed.
4G and 5G Useful for rapid deployment, temporary sites, and failover. Performance may fluctuate with coverage, signal strength, data limits, and congestion.
Satellite Useful where other options are unavailable. SD-WAN policy must account for its specific latency, weather, and capacity characteristics.

3. The Overlay: Where Intelligence Comes In

If the underlay is the highway system, the overlay is the intelligent fleet that selects routes according to business priorities. The SD-WAN overlay is the software layer that manages how the available underlay paths are used. It creates logical tunnels over physical connections and allows multiple transport services to be governed through a common policy model.

The overlay typically provides:

  • Application awareness: Identifies traffic such as voice, video, finance applications, SaaS, and general browsing so each category can be handled appropriately.
  • Centralized control: Allows WAN policies to be defined and managed from a common management system.
  • Dynamic path selection: Continuously checks link health and can move traffic to a better-performing path.
  • Encryption and security: Protects traffic through secure tunnels and can segment users, sites, and applications.
  • Visibility and analytics: Provides a consolidated view of network and application performance.
Important distinction: The overlay does not replace the underlay. It orchestrates the underlay and makes better decisions within the limits of the available circuits.

4. How Underlay and Overlay Work Together

Consider a branch office with three underlay links:

Underlay Link Typical Role
Dedicated fiber Primary business connectivity
Business broadband Cloud access and general internet traffic
5G Backup connectivity and rapid recovery

When a new traffic flow reaches the SD-WAN edge, the overlay evaluates questions such as:

  1. Which application is generating the traffic, such as a VoIP call or a file transfer?
  2. Which user, device, department, or site is sending it?
  3. What business priority should the traffic receive?
  4. Which links are currently available?
  5. Which available links meet the required bandwidth, latency, jitter, and packet-loss thresholds?
  6. Is there a preferred provider or link type?
  7. Should the traffic use one link or be distributed across several links?
  8. What should happen when the selected path degrades?

The overlay then applies the relevant policy. A VoIP call may use dedicated fiber because it currently offers the lowest jitter. Finance traffic may prefer fiber and fail over to broadband if the primary link becomes unavailable or falls below the required quality threshold. Approved SaaS traffic may use direct internet access over broadband, while guest traffic is routed separately and isolated from corporate segments.

SD-WAN underlay and overlay architecture diagram showing transport links, cloud gateway, and intelligent traffic routing.

5. Detecting Brownouts, Not Just Outages

A common network problem is not a total outage but a brownout. During a brownout, a link remains technically up and may still respond to basic probes, yet high packet loss, unstable latency, or excessive jitter causes applications to perform poorly. Traditional failover methods may miss this condition because the interface itself has not gone down.

SD-WAN platforms use active probes and health checks to measure the real-time quality of each path. These measurements are compared with thresholds defined for different application classes. If a path no longer satisfies the required profile — for example, latency becomes too high for voice — the overlay can move the application to a better path even though the original circuit remains available.

Application-specific quality matters: A path that is unsuitable for an interactive voice call may still be acceptable for email or a background software update.

6. Underlay vs. Overlay at a Glance

Feature Underlay Overlay
Main purpose Provides transport and IP reachability Controls how business traffic uses the available transport
Common elements MPLS, DIA, broadband, fiber, cellular, satellite Logical tunnels, policies, application rules, and segments
Ownership Carrier, ISP, or enterprise transport team SD-WAN platform and enterprise policy
Capacity Determined by purchased services and network conditions Prioritizes and allocates existing capacity
Path quality Experiences latency, jitter, packet loss, and congestion Measures performance and responds through policy
Traffic decisions Uses provider routing and transport mechanisms Adds centralized, application-aware path selection
Security Depends on the service and local controls Can add encrypted tunnels, segmentation, and consistent policy
Failure response May rely on interface state or routing convergence Can react to application-specific SLA violations
Flexibility Limited by services available at each site Uses different transport combinations under one policy model
Visibility Often divided across providers and individual devices Can provide a consolidated operational view

In simple terms, the underlay provides the roads and the overlay makes their use intelligent. By measuring and dynamically managing transport resources, SD-WAN can create a more responsive, resilient, and cost-effective WAN within the limits of the available network.

7. Practical Example: A Multi-Branch Organization

Consider an organization with a head office, a data center, and 75 branch offices. Each branch uses a primary broadband circuit, a secondary internet circuit, and a cellular backup. Employees depend on a cloud CRM, a centrally hosted ERP system, voice and video conferencing, collaboration tools, large file transfers, and guest internet access.

The underlay provides the available paths. The overlay converts those paths into application-specific behavior.

Traffic Category Example Overlay Policy
CRM and ERP Assign high priority and use the most stable qualifying path. Fail over when the selected path no longer meets the required quality profile.
Voice and video Select a path that satisfies the configured latency, jitter, and packet-loss thresholds.
Cloud applications Use approved direct internet access to avoid unnecessary data-center backhaul.
Guest Wi-Fi Use a separate internet route and keep traffic isolated from corporate segments.
Large file transfers Use a high-capacity transport while maintaining lower priority than interactive business traffic.
Cellular backup Carry designated critical applications during a wired outage and limit nonessential traffic to control data consumption.

This is the practical difference between simply owning three, four, or five circuits and operating an intelligent WAN. Multiple circuits create options; the overlay converts those options into controlled business outcomes.

8. What the Overlay Cannot Fix

SD-WAN introduces decision-making, but it does not remove the physical constraints of networking. The overlay cannot compensate for:

  • Insufficient capacity across every available path.
  • Two supposedly diverse circuits that share the same last-mile duct, pole, exchange, or upstream infrastructure.
  • Weak cellular signal, severe mobile-network congestion, or a broader carrier outage.
  • Incorrect routing, NAT, DNS, or firewall configuration.
  • Underpowered edge hardware.
  • Inadequate capacity planning.
  • Poorly selected SLA thresholds.
  • An unavailable destination application or cloud service.

Even when services come from different providers, they may still enter the building through the same physical duct or depend on the same upstream infrastructure. Diversity at one point in the network does not guarantee diversity across the entire path.

The overlay enables more effective choices within the environment it is given. Policy alone cannot make a physically weak or poorly designed underlay resilient.

9. Security Across the Two Layers

An underlay can be public or private. MPLS may be provisioned as a private service, while broadband and cellular traffic may traverse shared provider infrastructure.

The overlay may establish encrypted tunnels between authenticated edge devices. Platform-dependent security capabilities can include:

  • Network segmentation
  • Centralized firewall policy
  • Application control
  • Secure internet breakout
  • Certificate-based device trust
  • Integration with cloud-delivered security services
  • Centralized logging and monitoring

Encryption is important, but it is only one part of a broader Zero Trust or SASE architecture. A wider design may also include identity authentication, endpoint posture checks, least-privilege access, threat prevention, DNS security, and protected web browsing.

10. Common Design Mistakes

Treating every link as equal

MPLS, DIA, broadband, and 5G differ in capacity, latency, cost, and reliability. Policy should reflect those differences.

Selecting thresholds without testing

Thresholds that are too strict can cause unnecessary path changes. Thresholds that are too loose can leave critical applications on degraded links.

Assuming two providers guarantee diversity

Providers may share a duct, exchange, pole, or upstream route. Validate both physical and logical diversity.

Ignoring upload capacity

A high download rate does not guarantee sufficient upstream capacity for meetings, backups, or site-to-site applications.

Assuming every failover is seamless

The impact of a path change depends on application behavior, NAT state, tunnel architecture, and the traffic-steering method. Some sessions may need to reconnect.

Using SD-WAN to hide a capacity deficit

Prioritization can protect critical traffic during short congestion periods, but it cannot replace bandwidth and capacity planning.

11. Questions to Ask Before Deployment

Underlay Questions

  • How much downstream and upstream capacity does each site require?
  • Which applications are sensitive to delay, jitter, or packet loss?
  • Are the providers and physical paths genuinely diverse?
  • Is cellular coverage stable and properly tested?
  • Are public IP addresses required?
  • What service levels and repair targets apply?
  • Do the links share a common point of failure?
  • Is adequate capacity available during peak hours?

Overlay Questions

  • Which applications should receive priority?
  • What quality thresholds are appropriate for each traffic class?
  • How should traffic fail over and return to the preferred path?
  • Which applications require direct internet access?
  • How should corporate, guest, voice, IoT, and management traffic be segmented?
  • Which topology is appropriate: hub-and-spoke, full mesh, or dynamic mesh?
  • How will the platform integrate with routing and security systems?
  • How will policies be tested before a large rollout?

12. Does SD-WAN Replace MPLS?

Not necessarily. SD-WAN can reduce dependence on MPLS without requiring its complete removal. In a hybrid design, MPLS may continue to support selected private or critical applications, DIA may serve public cloud and SaaS traffic, broadband may provide additional capacity, and 5G may provide backup connectivity.

The decision to retain, reduce, or replace MPLS depends on application requirements, location, transport availability, compliance, risk tolerance, and total cost. SD-WAN changes the design choice: instead of forcing all traffic over one service, the organization can select the most appropriate transport for each application.

13. Frequently Asked Questions

Can an SD-WAN overlay operate without an underlay?

No. The overlay requires IP reachability between endpoints so its logical tunnels can carry traffic.

Can an underlay operate without SD-WAN?

Yes. Traditional WANs can operate over MPLS, leased lines, broadband, or internet VPNs. SD-WAN adds centralized policy, visibility, and dynamic traffic steering across diverse network inputs.

Is the overlay the same as a VPN?

No. A VPN tunnel can be part of an overlay, but SD-WAN also adds application-aware path selection, health monitoring, segmentation, and centralized policy.

Does SD-WAN combine the bandwidth of every link?

It depends on the platform and the traffic-distribution method. Multiple sessions may be distributed across links, but a single session does not automatically gain the combined speed of all circuits.

Is every overlay tunnel encrypted?

Many enterprise platforms support encrypted tunnels, but the protocol, algorithm, configuration, and operational requirements vary by platform.

Which layer is more important?

Neither layer produces the complete outcome alone. The underlay supplies connectivity and capacity; the overlay controls those resources according to application, security, and business requirements.

14. Conclusion

Making a WAN intelligent requires more than simply adding circuits.

The underlay provides capacity, availability, and physical resilience at each site. The overlay provides intelligence by continuously monitoring paths, identifying applications, enforcing policy, and adapting to changing network conditions.

A successful SD-WAN deployment designs both layers together. Reliable transport is underused without intelligent policy, while intelligent policy has too little to work with when the transport is weak or poorly designed.

Final takeaway: The underlay defines the available paths. The overlay uses those paths to achieve business outcomes.

 

Vipul Meh

Network Engineer

Vipul Meh

Vipul Meh is a Network Engineer with expertise in designing, deploying, and troubleshooting secure enterprise network architectures. His technical experience includes SD-WAN, hub-and-spoke topologies, LAN/WAN design, policy-based and route-based IPsec VPNs, VRRP, VXLAN, High Availability, multi-vendor firewalls, routing, NAT, and traffic-security policies. He specializes in root-cause analysis of network failures using packet-level diagnostics, CLI tools, logs, traceroute, traffic-flow validation, and performance benchmarking. His work focuses on resolving VPN negotiation failures, routing inconsistencies, packet drops, failover delays, throughput degradation, and firewall-policy issues. Through his blogs on ray.life, he documents real deployment scenarios and practical troubleshooting approaches for network engineers and IT professionals.

Recent Posts