SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

A branch network now manages applications, not circuits.

As applications moved from the data center to cloud, a branch design that hauls all traffic to headquarters became both slow and expensive. An SD-WAN decision requires application, link and security policy to be considered together.

SD-WAN starting as a circuit cost-cutting project usually ends in disappointment. The real gain is that application performance and policy consistency become measurable.

Application priority and path selection

Traffic is placed on a path according to what the application needs: real-time flows on the most stable link, bulk transfer on the cheapest. Link quality is measured continuously and the path changes on its own when quality degrades.

  • The application recognition list is kept current
  • Path changes happen without dropping sessions
  • Quality thresholds differ per application
  • Backup links are tested even while unused

Secure access and policy

Breaking out directly from branch to cloud risks bypassing central security controls. Policy must produce the same outcome regardless of where traffic leaves, and access is matched to identity and device posture.

  • The same policy yields the same result at HQ and branch
  • Direct internet breakout stays under control
  • Access is tied to identity and device posture
  • Policy exceptions are time-bound and recorded

Branch rollout and operation

Opening a new branch should take hours on the network side, not days. Template-based provisioning and central management make rollout possible without sending a specialist to site.

  • Branch templates are managed from one place
  • Rollout needs no on-site specialist
  • Changes are trialed at a single branch first
  • Rollback can be performed centrally

Measurement and migration plan

Migration starts by measuring current performance; without that any improvement claim stays unproven. Branches move in waves, and the same indicators are compared after every wave.

  • Pre-migration performance is recorded per branch
  • Wave size follows the capacity to roll back
  • Each wave is read against the identical indicator set
  • Old circuits stay live until measurement confirms the new path

How we work

  1. Inventory applications and their priority
  2. Measure current branch performance
  3. Define policy and path rules
  4. Migrate branches in waves
  5. Compare the same indicators at every wave

How success is measured

  • Critical application performance beats the pre-migration baseline
  • Policy produces identical results at HQ and branch
  • Time to bring up a new branch has shortened
  • Backup links are tested and proven working

Frequently asked questions

Do we have to change our circuits?

Not necessarily. SD-WAN can combine different link types; the decision follows measured quality and cost. Changing circuits is a separate decision.

Where will security be enforced?

What matters is not where the policy runs but that its outcome is the same. It can be enforced at the branch, in cloud or centrally; the choice follows latency and inspection needs.

Do branches go offline while they are migrated?

The wave plan and a per-branch rollback path limit it. Each branch gets its own migration window, and the old path stays available until measurement confirms the new one.

Let's measure your branch performance as it stands today and discuss what SD-WAN would actually change, with evidence.

Let's measure branch performance