CCDE Enterprise Case Study Part 17 – Designing a Fully Resilient SD-WAN Headend for Jacobs DC
As Jacobs transitions toward a modern SD-WAN architecture, one of the most important enterprise design decisions involves placement of the SD-WAN headend routers inside the data center.
This is not simply a routing exercise.
It is a:
- Security design problem
- Scalability challenge
- Migration architecture challenge
- Traffic engineering challenge
- Resiliency engineering exercise
๐ฏ Key Enterprise Objective
Design a fully resilient SD-WAN headend architecture that:
- Supports MPLS and Internet transports simultaneously
- Maintains secure segmentation
- Avoids single points of failure
- Enables gradual migration from MPLS to SD-WAN
- Protects SD-WAN edge routers from direct Internet exposure
Table of Contents
- 1. Understanding the Problem Statement
- 2. Key Design Requirements
- 3. Optimal SD-WAN Headend Topology
- 4. Why Router Placement Matters
- 5. Resiliency Analysis
- 6. Traffic Flow Engineering
- 7. Alternative Designs and Their Problems
- 8. SD-WAN Capacity and Scaling Mathematics
- 9. Example SD-WAN CLI Configurations
- 10. AI and Analytics in SD-WAN
- 11. Related Articles
1. Understanding the Problem Statement
Jacobs currently operates:
- Dual MPLS providers
- Traditional WAN architecture
- Centralized Internet breakout
- Large-scale MPLS connectivity
The organization now wants:
- Dual 10Gbps Internet connectivity
- Migration toward SD-WAN
- Reduction from dual MPLS headends to a single MPLS provider
- A resilient SD-WAN architecture
This means the new architecture must simultaneously support:
$$ Legacy\\ MPLS + Modern\\ SD\\text{-}WAN $$during migration.
๐ก Enterprise Design Insight
Most enterprise WAN transformations fail because architects ignore:
- Migration coexistence
- Operational continuity
- Traffic path optimization
- Security zoning
Jacobs specifically requires:
$$ Zero\\ Major\\ Disruption $$2. Key Design Requirements
| Requirement | Why It Matters |
|---|---|
| Dual SD-WAN edge routers | Eliminates single points of failure |
| 10Gbps connectivity | Supports future WAN growth |
| Protected Internet access | Prevents direct exposure |
| Direct MPLS connectivity | Optimizes MPLS forwarding |
| DC connectivity | Allows local application access |
| Migration coexistence | Supports non-SD-WAN stores |
3. Optimal SD-WAN Headend Topology
The correct design requires:
- Two SD-WAN edge routers
- Direct Internet-facing interfaces
- Direct MPLS-facing interfaces
- Direct DC-facing interfaces
Required Interface Formula
$$ Interfaces = Internet + MPLS + DC $$Per edge router:
$$ 3\\ Interfaces\\ Minimum $$Correct Traffic Flow
DC → SD-WAN Edge → MPLS or Internet
The SD-WAN edge router becomes:
$$ The\\ Central\\ Policy\\ Decision\\ Point $$4. Why Router Placement Matters
One of the most important architectural decisions is:
$$ Where\\ To\\ Place\\ The\\ SD\\text{-}WAN\\ Edge $$Correct Placement
The SD-WAN edge routers should sit:
- Behind the DMZ
- Inside the protected zone
- Not directly exposed to the Internet
Why This Matters
If SD-WAN edge routers are directly exposed:
- Attack surface increases
- DDoS exposure increases
- Control-plane attacks become possible
- Management-plane exploitation risk rises
๐ก Security Design Principle
$$ Protected\\ Edge > Internet\\ Exposed\\ Edge $$Traffic Security Flow
Internet ↓ Outer DMZ ↓ Firewall ↓ Inner DMZ ↓ SD-WAN Edge Router
This layered design follows:
$$ Defense\\ in\\ Depth $$5. Resiliency Analysis
The architecture removes:
- Single router failure
- Single MPLS path failure
- Single Internet path failure
- Single edge forwarding failure
Resiliency Formula
Dual Edge Benefits
| Single Edge | Dual Edge |
|---|---|
| Single failure kills WAN | WAN survives router failure |
| Maintenance outage impacts traffic | Hitless maintenance possible |
| Limited scaling | Horizontal scaling possible |
Why Direct MPLS Links Matter
The MPLS router connects directly to the SD-WAN edge routers.
Without this:
$$ Traffic\\ Ping\\ Pongs $$through the DC unnecessarily.
6. Traffic Flow Engineering
Optimal MPLS Flow
DC → SD-WAN Edge → MPLS Router → MPLS Cloud
Optimal Internet Flow
DC → SD-WAN Edge → Firewall → Internet
Why This Is Efficient
The SD-WAN edge router performs:
- Path selection
- Application steering
- SLA analysis
- Overlay routing decisions
before traffic leaves the DC.
Path Selection Formula
$$ Best\\ Path = Latency + Jitter + Loss + Business\\ Policy $$7. Alternative Designs and Their Problems
Alternative 1 – No Direct MPLS Connection
DC → Edge → DC → MPLS Router
Problem
- Traffic hairpinning
- Extra latency
- Inefficient forwarding
- Higher WAN core load
Alternative 2 – Remove DC-to-MPLS Connectivity
Problem
This breaks coexistence migration.
Some stores still use:
$$ Traditional\\ MPLS $$during migration.
Traffic must still flow directly:
MPLS → DC
without passing through SD-WAN unnecessarily.
Alternative 3 – Single SD-WAN Edge Router
Problem
- Single point of failure
- Maintenance outage risk
- Control-plane failure risk
8. SD-WAN Capacity and Scaling Mathematics
Bandwidth Scaling
$$ Total\\ Capacity = MPLS + Internet $$For Jacobs:
$$ 10Gbps + 10Gbps $$Tunnel Scaling
$$ Tunnels \propto n(n-1) $$Failure Domain Reduction
$$ Risk \propto \frac{1}{Redundancy} $$WAN Path Optimization
$$ Optimal\\ Path = Minimum\\ SLA\\ Violation $$9. Example SD-WAN CLI Configurations
Example – WAN Transport Interface
interface GigabitEthernet0/0 description INTERNET_TRANSPORT ip address 100.1.1.2 255.255.255.252 tunnel-interface encapsulation ipsec
Example – MPLS Transport Interface
interface GigabitEthernet0/1 description MPLS_TRANSPORT ip address 172.16.1.2 255.255.255.252 tunnel-interface color mpls
Example – OMP Overlay Routing
omp no shutdown graceful-restart
Example – SLA Policy
app-route-policy WAN_POLICY sequence 10 match application office365 action accept set preferred-color biz-internet
10. AI and Analytics in SD-WAN
Modern SD-WAN increasingly relies on:
- Machine learning
- Predictive analytics
- Anomaly detection
- Path prediction
to optimize:
- Application steering
- Transport selection
- Congestion prediction
- Capacity planning
Useful Data Science Articles
- Time Series Forecasting Beginners Guide
- Stationary vs Nonstationary Data
- How to Evaluate and Ensure Your Data
11. Related Articles
CCDE Enterprise Case Study Series
- Part 1 – Enterprise Architecture
- Part 2 – Business Analysis
- Part 3 – Scalability
- Part 4 – MPLS Analysis
- Part 5 – MPLS Design
- Part 6 – DMVPN
- Part 7 – WAN Evolution
- Part 8 – SD-WAN Introduction
- Part 9 – SD-WAN Security
- Part 10 – WAN Transformation
- Part 11 – Self-Managed SD-WAN
- Part 12 – SD-WAN Architecture
- Part 13 – WAN Design
- Part 14 – Internet Connectivity
- Part 15 – 5G and DIA
- Part 16 – Toolmate Integration
- Part 18 - CCDE SD-WAN Branch Design Explained: Best Hybrid MPLS and Internet Architecture for Enterprise Stores
CCIE and Enterprise WAN Concepts
- Complete MPLS L3VPN Configuration Lab
- Complete MPLS QoS Configuration Lab
- Optimizing OSPF Timers for Faster Convergence
- Reliable BGP Peering and Physical Connectivity
- Modern Web Filtering with Cisco ASA
- Enhancing IKE Phase 1 Security
Final Conclusion
The optimal Jacobs SD-WAN headend design uses:
- Dual SD-WAN edge routers
- Direct MPLS connectivity
- Protected Internet access via DMZ
- Direct DC connectivity
- Layered security zones
This design achieves:
$$ Security + Scalability + Migration\\ Flexibility + Operational\\ Resilience $$which are all critical requirements for large-scale enterprise SD-WAN deployments.
Most importantly, the architecture supports:
- Coexistence migration
- Hybrid WAN operations
- Application-aware routing
- Future cloud integration
while avoiding:
- Single points of failure
- Traffic hairpinning
- Operational complexity
- Direct Internet exposure
No comments:
Post a Comment