Monday, May 18, 2026

CCDE SD-WAN Design Part 16 – Can Toolmate Remove Its Internet Edge?

CCDE Enterprise Case Study Part 16 – Can Toolmate Remove Its Internet Edge?

CCDE Enterprise Case Study Part 16 – Can Toolmate Remove Its Internet Edge?

As Jacobs moves deeper into SD-WAN transformation, one of the most important architectural decisions now emerges:

Question 15

Can Toolmate fully decommission its local Internet edge and instead use the upgraded 10Gbps resilient Internet edge at Jacobs DC as a secondary SD-WAN termination point?

Correct Answer:

❌ No

Toolmate still requires its own Internet edge because:

  • Public-facing Toolmate services still exist locally
  • B2B VPN connectivity terminates locally
  • DMZ applications rely on Toolmate ISP presence
  • Removing the Internet edge introduces architectural dependency risks

Table of Contents

1. Understanding the Design Problem

James Medina proposes:

  • Replacing secondary MPLS links with Internet circuits
  • Migrating to SD-WAN overlays
  • Using Jacobs DC as centralized resilient Internet access
  • Potentially removing Toolmate Internet connectivity

At first glance, this appears logical.

If:

$$ Jacobs\\ DC\\ Internet\\ Capacity \ge Toolmate\\ Requirements $$

then perhaps:

$$ One\\ Shared\\ Internet\\ Edge $$

could reduce:

  • Operational cost
  • Circuit cost
  • Management complexity

However:

๐Ÿ’ก Critical Architectural Principle

WAN transport resiliency does NOT automatically replace:

$$ Local\\ Service\\ Dependencies $$

2. Why the Answer Is No

The key requirement appears here:

The DMZ hosts a single non-load-balanced DMZ segment
for publicly reachable web services for the Toolmate online presence.

This means:

  • Toolmate hosts Internet-facing applications
  • Toolmate requires inbound Internet reachability
  • Toolmate maintains public services locally

Therefore:

$$ Toolmate\\ ISP\\ Edge \neq Branch\\ Internet\\ Access\\ Only $$

Instead:

$$ Toolmate\\ ISP\\ Edge = Critical\\ Public\\ Service\\ Infrastructure $$

Why This Is Important

Many engineers incorrectly assume:

$$ Internet\\ Edge = User\\ Internet\\ Browsing $$

But enterprise Internet edges often provide:

  • DMZ hosting
  • B2B VPNs
  • Public web applications
  • NAT services
  • External DNS services
  • Partner connectivity

Removing the Toolmate ISP edge would therefore break:

  • Toolmate online store access
  • External B2B integrations
  • Public application reachability

3. SD-WAN Underlay Transformation

The architecture evolves from:

$$ Dual\\ MPLS $$

toward:

$$ MPLS + DIA $$

where:

  • MPLS provides deterministic enterprise transport
  • DIA provides low-cost Internet underlay
  • SD-WAN overlays abstract transport selection

Hybrid WAN Equation

$$ Hybrid\\ WAN = MPLS + Broadband + LTE + Policy $$

Why Enterprises Like Hybrid WAN

MPLS Internet
Predictable latency Lower cost
QoS support High bandwidth
Enterprise SLA Rapid deployment
Private transport Cloud optimized

SD-WAN intelligently combines both.

4. Internet Edge Architecture

A modern Internet edge performs:

  • NAT
  • Firewall inspection
  • DDoS mitigation
  • Public application publishing
  • VPN termination
  • Security inspection

Toolmate currently hosts:

  • Online retail services
  • Tool hire systems
  • B2B VPN services

Therefore:

$$ Removing\\ Toolmate\\ Internet\\ Edge $$

creates:

$$ Service\\ Dependency\\ Risk $$

5. DMZ Dependency Analysis

Toolmate uses:

$$ DMZ\\ Architecture $$

for:

  • Public-facing applications
  • Internet separation
  • Security zoning

Important Design Observation

The Toolmate DMZ is:

single non-load-balanced DMZ segment

This already introduces:

  • Single points of failure
  • Scalability limitations
  • Operational risk

Removing the local ISP would worsen:

$$ Dependency\\ Concentration $$

Risk Concentration Formula

$$ Risk \propto Dependency\\ Density $$

6. DCI and Fate Sharing Risks

If Toolmate relied entirely on Jacobs Internet access:

$$ Toolmate\\ Internet = Jacobs\\ ISP + DCI + Jacobs\\ Firewalls $$

This creates:

  • Fate sharing
  • Interdependency
  • Failure domain expansion

Failure Scenario Example

Failure Impact
Jacobs ISP outage Both Jacobs and Toolmate affected
DCI outage Toolmate isolated from Internet
Jacobs firewall issue Toolmate public services fail

๐ŸŽฏ Enterprise Architecture Principle

Do not centralize services if doing so:

$$ Increases\\ Failure\\ Blast\\ Radius $$

7. Enterprise WAN Mathematics

Availability Formula

$$ Availability = \frac{MTBF}{MTBF + MTTR} $$

Compound Dependency Formula

$$ Total\\ Availability = A_1 \times A_2 \times A_3 $$

If Toolmate depends on:

  • DCI
  • Jacobs ISP
  • Jacobs Firewall

then overall availability becomes:

$$ A_{total} = A_{DCI} \times A_{ISP} \times A_{Firewall} $$

This often reduces overall resiliency.

8. SD-WAN Configuration Examples

Example – DIA Tunnel Interface

interface Tunnel100

 ip unnumbered GigabitEthernet0/0

 tunnel source GigabitEthernet0/0

 tunnel mode ipsec ipv4

Example – SD-WAN SLA Policy

policy

 app-route-policy CRITICAL-VOICE

  sequence 10

   match application voip

   action accept

    set preferred-color mpls

Example – Internet Backup Policy

policy

 app-route-policy INTERNET-BACKUP

  sequence 20

   match application all

   action accept

    set preferred-color biz-internet

9. Security Design Considerations

James Medina proposes:

$$ SD\\text{-}WAN\\ Native\\ Security $$

instead of dedicated store firewalls.

This reduces:

  • Hardware cost
  • Operational complexity
  • Rack footprint

However:

  • Policy consistency becomes critical
  • DIA security must be locally enforced
  • ZTNA becomes important
  • SASE evolution becomes likely

Useful Security References

10. Machine Learning and WAN Analytics

Modern SD-WAN solutions increasingly use:

  • Machine learning
  • Predictive analytics
  • Anomaly detection
  • Traffic forecasting

for:

  • SLA prediction
  • Path optimization
  • Capacity planning
  • Congestion avoidance

Useful Analytics References

CCDE Enterprise Case Study Series

Final Conclusion

Although SD-WAN provides:

  • Transport abstraction
  • Dynamic failover
  • Hybrid WAN flexibility

it does NOT automatically eliminate:

$$ Local\\ Internet\\ Service\\ Dependencies $$

Toolmate still requires:

  • Public-facing services
  • DMZ hosting
  • B2B VPN connectivity
  • Independent Internet presence

Therefore:

❌ Toolmate cannot safely decommission its Internet edge.

Doing so would:

  • Increase dependency on Jacobs infrastructure
  • Create fate-sharing risks
  • Expand failure domains
  • Threaten public service availability

No comments:

Post a Comment

Featured Post

How HMT Watches Lost the Time: A Deep Dive into Disruptive Innovation Blindness in Indian Manufacturing

The Rise and Fall of HMT Watches: A Story of Brand Dominance and Disruptive Innovation Blindness The Rise and Fal...

Popular Posts