Monday, May 18, 2026

CCDE SD-WAN Design Part 17: Building a Fully Resilient Enterprise SD-WAN Headend Architecture

CCDE Enterprise Case Study Part 17 – Designing a Fully Resilient SD-WAN Headend for Jacobs DC

CCDE Enterprise Case Study Part 17 – Designing a Fully Resilient SD-WAN Headend for Jacobs DC

As Jacobs transitions toward a modern SD-WAN architecture, one of the most important enterprise design decisions involves placement of the SD-WAN headend routers inside the data center.

This is not simply a routing exercise.

It is a:

  • Security design problem
  • Scalability challenge
  • Migration architecture challenge
  • Traffic engineering challenge
  • Resiliency engineering exercise

๐ŸŽฏ Key Enterprise Objective

Design a fully resilient SD-WAN headend architecture that:

  • Supports MPLS and Internet transports simultaneously
  • Maintains secure segmentation
  • Avoids single points of failure
  • Enables gradual migration from MPLS to SD-WAN
  • Protects SD-WAN edge routers from direct Internet exposure

Table of Contents

1. Understanding the Problem Statement

Jacobs currently operates:

  • Dual MPLS providers
  • Traditional WAN architecture
  • Centralized Internet breakout
  • Large-scale MPLS connectivity

The organization now wants:

  • Dual 10Gbps Internet connectivity
  • Migration toward SD-WAN
  • Reduction from dual MPLS headends to a single MPLS provider
  • A resilient SD-WAN architecture

This means the new architecture must simultaneously support:

$$ Legacy\\ MPLS + Modern\\ SD\\text{-}WAN $$

during migration.

๐Ÿ’ก Enterprise Design Insight

Most enterprise WAN transformations fail because architects ignore:

  • Migration coexistence
  • Operational continuity
  • Traffic path optimization
  • Security zoning

Jacobs specifically requires:

$$ Zero\\ Major\\ Disruption $$

2. Key Design Requirements

Requirement Why It Matters
Dual SD-WAN edge routers Eliminates single points of failure
10Gbps connectivity Supports future WAN growth
Protected Internet access Prevents direct exposure
Direct MPLS connectivity Optimizes MPLS forwarding
DC connectivity Allows local application access
Migration coexistence Supports non-SD-WAN stores

3. Optimal SD-WAN Headend Topology

The correct design requires:

  • Two SD-WAN edge routers
  • Direct Internet-facing interfaces
  • Direct MPLS-facing interfaces
  • Direct DC-facing interfaces

Required Interface Formula

$$ Interfaces = Internet + MPLS + DC $$

Per edge router:

$$ 3\\ Interfaces\\ Minimum $$

Correct Traffic Flow

DC → SD-WAN Edge → MPLS or Internet

The SD-WAN edge router becomes:

$$ The\\ Central\\ Policy\\ Decision\\ Point $$

4. Why Router Placement Matters

One of the most important architectural decisions is:

$$ Where\\ To\\ Place\\ The\\ SD\\text{-}WAN\\ Edge $$

Correct Placement

The SD-WAN edge routers should sit:

  • Behind the DMZ
  • Inside the protected zone
  • Not directly exposed to the Internet

Why This Matters

If SD-WAN edge routers are directly exposed:

  • Attack surface increases
  • DDoS exposure increases
  • Control-plane attacks become possible
  • Management-plane exploitation risk rises

๐Ÿ’ก Security Design Principle

$$ Protected\\ Edge > Internet\\ Exposed\\ Edge $$

Traffic Security Flow

Internet
   ↓
Outer DMZ
   ↓
Firewall
   ↓
Inner DMZ
   ↓
SD-WAN Edge Router

This layered design follows:

$$ Defense\\ in\\ Depth $$

5. Resiliency Analysis

The architecture removes:

  • Single router failure
  • Single MPLS path failure
  • Single Internet path failure
  • Single edge forwarding failure

Resiliency Formula

$$ Availability = 1 - (Failure\\ Probability) $$

Dual Edge Benefits

Single Edge Dual Edge
Single failure kills WAN WAN survives router failure
Maintenance outage impacts traffic Hitless maintenance possible
Limited scaling Horizontal scaling possible

Why Direct MPLS Links Matter

The MPLS router connects directly to the SD-WAN edge routers.

Without this:

$$ Traffic\\ Ping\\ Pongs $$

through the DC unnecessarily.

6. Traffic Flow Engineering

Optimal MPLS Flow

DC → SD-WAN Edge → MPLS Router → MPLS Cloud

Optimal Internet Flow

DC → SD-WAN Edge → Firewall → Internet

Why This Is Efficient

The SD-WAN edge router performs:

  • Path selection
  • Application steering
  • SLA analysis
  • Overlay routing decisions

before traffic leaves the DC.

Path Selection Formula

$$ Best\\ Path = Latency + Jitter + Loss + Business\\ Policy $$

7. Alternative Designs and Their Problems

Alternative 1 – No Direct MPLS Connection

DC → Edge → DC → MPLS Router

Problem

  • Traffic hairpinning
  • Extra latency
  • Inefficient forwarding
  • Higher WAN core load

Alternative 2 – Remove DC-to-MPLS Connectivity

Problem

This breaks coexistence migration.

Some stores still use:

$$ Traditional\\ MPLS $$

during migration.

Traffic must still flow directly:

MPLS → DC

without passing through SD-WAN unnecessarily.

Alternative 3 – Single SD-WAN Edge Router

Problem

  • Single point of failure
  • Maintenance outage risk
  • Control-plane failure risk

8. SD-WAN Capacity and Scaling Mathematics

Bandwidth Scaling

$$ Total\\ Capacity = MPLS + Internet $$

For Jacobs:

$$ 10Gbps + 10Gbps $$

Tunnel Scaling

$$ Tunnels \propto n(n-1) $$

Failure Domain Reduction

$$ Risk \propto \frac{1}{Redundancy} $$

WAN Path Optimization

$$ Optimal\\ Path = Minimum\\ SLA\\ Violation $$

9. Example SD-WAN CLI Configurations

Example – WAN Transport Interface

interface GigabitEthernet0/0

 description INTERNET_TRANSPORT

 ip address 100.1.1.2 255.255.255.252

 tunnel-interface

  encapsulation ipsec

Example – MPLS Transport Interface

interface GigabitEthernet0/1

 description MPLS_TRANSPORT

 ip address 172.16.1.2 255.255.255.252

 tunnel-interface

  color mpls

Example – OMP Overlay Routing

omp

 no shutdown

 graceful-restart

Example – SLA Policy

app-route-policy WAN_POLICY

 sequence 10

  match application office365

  action accept

   set preferred-color biz-internet

10. AI and Analytics in SD-WAN

Modern SD-WAN increasingly relies on:

  • Machine learning
  • Predictive analytics
  • Anomaly detection
  • Path prediction

to optimize:

  • Application steering
  • Transport selection
  • Congestion prediction
  • Capacity planning

Useful Data Science Articles

CCDE Enterprise Case Study Series

CCIE and Enterprise WAN Concepts

Final Conclusion

The optimal Jacobs SD-WAN headend design uses:

  • Dual SD-WAN edge routers
  • Direct MPLS connectivity
  • Protected Internet access via DMZ
  • Direct DC connectivity
  • Layered security zones

This design achieves:

$$ Security + Scalability + Migration\\ Flexibility + Operational\\ Resilience $$

which are all critical requirements for large-scale enterprise SD-WAN deployments.

Most importantly, the architecture supports:

  • Coexistence migration
  • Hybrid WAN operations
  • Application-aware routing
  • Future cloud integration

while avoiding:

  • Single points of failure
  • Traffic hairpinning
  • Operational complexity
  • Direct Internet exposure

No comments:

Post a Comment

Featured Post

How HMT Watches Lost the Time: A Deep Dive into Disruptive Innovation Blindness in Indian Manufacturing

The Rise and Fall of HMT Watches: A Story of Brand Dominance and Disruptive Innovation Blindness The Rise and Fal...

Popular Posts