Enterprises seeking private WAN services have more choices today than ever, including MPLS, SD-WAN and secure access service edge (SASE). The range of choices and the blurring of which features belong to what services makes it challenging for IT leaders to choose the right private WAN service, or combination of services, to meet their organizations’ needs.

According to Shamus McGillicuddy, VP of research for Enterprise Management Associates (EMA), the rise of SD-WAN roughly a decade ago “kicked off multiple waves of innovation as startups delivered solutions that made expensive routers and firewalls redundant in many remote sites. SD-WAN also triggered waves of mergers and acquisitions when Router and firewall vendors bought SD-WAN providers to preserve and extend the value of their existing solutions.”

WAN innovation keeps marching onward, and today new options have emerged, including SASE, security services edge (SSE) and even 5G.

To help your organization navigate its many WAN choices, here are four questions to ask as you evaluate private WAN solutions.  

1 What does your current WAN look like? 

Before digging into software-defined, cloud-delivered private WAN options, the first factor organizations should consider is their existing WAN investments.

Large enterprises that have already built out WAN infrastructure will be reluctant to walk away from those investments. Similarly, businesses that rely on MPLS to support mission-critical applications may still require SLAs guaranteeing reliable bandwidth, low data loss and low latency. Since SD-WAN vendors do not control the underlying connectivity, they are not able to match those SLAs.

Similarly, organizations that originally deployed SD-WAN for traditional use cases, such as connectivity to branch offices, may prefer to add to those investments rather than replacing them with similar software services that may well blend together with SD-WAN over time, as the overall software-based WAN market continues to evolve.

2. Are you willing to deploy SD-WAN as part of a hybrid WAN? 

Even if your organization is a large Enterprise with MPLS-related path dependencies, you needn’t rip and replace MPLS to gain SD advantages over your WAN traffic. What many enterprises do instead is augment MPLS with SD-WAN. There are many benefits to this approach, including the capability to aggregate bandwidth, prioritize various types of traffic, and improve connections to remote and Work-from-Home (WFH) employees.

In fact, many telcos offer a range of hybrid WAN services, including MPLS, SD-WAN and SASE, that they will manage for you. One reason why MPLS is still going strong is that providers can augment it with other managed services, which not only helps them avoid cannibalizing their existing customer base, but also can extend the life of legacy deployments. According to the research firm IMARC Group, the worldwide managed MPLS market grew to $60B in 2022 and is forecast to expand to $80.6B by 2028.

The downside to the hybrid WAN approach, however, is increased complexity. This doesn’t bother service providers, who will happily take on the high-margin task of managing all of your private WAN connections. For enterprises that handle networking internally, however, hybrid WANs often create too many headaches for already resource-strapped teams.

3. Do you prefer a security-first approach to the WAN? 

For many organizations, the main roadblock halting digital transformation efforts is security. Large enterprises with small IT departments need simple, secure WAN services that scale. This was the case with O-I, formerly Owens Illinois (O-I), one of the world’s largest glass bottle and jar manufacturers. O-I had been relying on a carrier-based MPLS network, but it was showing signs of age as O-I slowly transitioned to a cloud-enabled, hybrid work environment.

“We were a long-term traditional MPLS customer with the typical routers on the edge, network-based firewall appliances, and legacy VPN concentrators,” said O-I’s CIO Rodney Masney. “As we reached the end of our agreements, we felt the time had come to rethink our approach to networking and security.”

O-I had been transitioning applications to the cloud, with a broad implementation of Microsoft 365 and plans for other Software-as-a-Service and cloud services. “There simply wasn’t enough bandwidth for all we had to do, whether it was SharePoint access, Microsoft Teams video conferencing, or working with our other cloud and internal applications,” Masney said. “We needed a cost-effective way to increase bandwidth to our locations and to the cloud.”

This is exactly the type of use case that SD-WAN originally targeted. However, security has always been a top priority for O-I’s small IT team, and managing security tools also consumed a disproportionate amount of IT’s time and resources. Simply maintaining and refreshing multiple legacy firewall appliances took scarce time and resources away from other digital transformation initiatives.

According to Masney, the final nail in the MPLS coffin was the sudden explosion of the COVID-19 epidemic, when O-I, like so many other companies, had to start serving a massive work-from-jome (WFH) staff. “We had to send thousands of employees home where it was challenging for our legacy VPN to provide the bandwidth and utility executives and other staff needed every day to get their work done,” Masney said.

Considering the security and connectivity challenges, O-I went with SASE from Tel Aviv-based Cato Networks. In a few months, O-I managed to deploy Cato SASE to 200 locations, completely replacing MPLS. O-I says that switching to SASE not only improved security in 70 plants located in 19 different countries, but it also boosted cloud and internal Application performance, while also serving as a key enabling technology that helped smooth the WFH transition and bolster security at once.

4. Are you willing to wait for SSE, networking-as-a-service (NaaS), 5G or whatever is next?

Enterprises that pit MPLS vs. SD-WAN/SASE are fighting the last war. SD-WAN offerings already blur with SASE ones, and managed service providers allow customers to pick and choose among various private WAN services to create various types of hybrid WANs.

Certain vendors are differentiating themselves by focusing on the network edge, offering SSE WAN service, while others are rolling out zero-trust network access (ZTNA) either as a standalone service or as part of SD-WAN/SASE platforms.

One private WAN startup, Graphiant, offers what it calls network-as-a-service, or NaaS. At first glance, Graphiant NaaS looks a whole lot like SD-WAN. This shouldn’t be a surprise, since Graphiant’s founder and CEO, Khalid Raza, previously served as CTO and co-founder of Viptela, an early mover in the SD-WAN space. After Cisco acquired Viptela for $610 million in 2017, Raza served as a distinguished engineer at Cisco. According to Raza, what makes NaaS different than other private WAN services is its “stateless core,” which separates the data from control plane and uses metadata headers to route traffic.

If that’s not enough variety, as 5G deployments continue to expand, innovations like Reduced-Capability (RedCap) 5G, which is designed to support constrained IoT devices, could muscle into the private WAN market. 5G providers are already targeting private WAN use cases, such as industrial IoT and Enterprise wearables.

In the near term, the private WAN market will remain fractured, but it will also offer enterprises an abundance of choice. As your organization evaluates its options, taking the time to assess your existing investments, evolving risk profile, and expanding edge access requirements will help you zero in on a service that best matches both your current and future needs.