At its core, SD-WAN is designed to provide secure and reliable communications between the branch and headquarters. But what if in doing so, SD-WAN is contributing to poor network performance?
That's the question posed by optical transport and routing vendor Ekinops in a blog post last week.
"In its current incarnation, SD-WAN could end up requiring two or three times the bandwidth of normal traffic, becoming a primary contributor to poor network performance; that would then require yet more SD-WAN to compensate," wrote Marc Bouteyre, head of virtual network function (VNF) management at Ekinops.
Bouteyre makes the case that while SD-WAN can more intelligently route traffic across the WAN, these platforms often make bad assumptions that the underlying network is insecure and unreliable. This has led to products that must constantly assess the network for disruptions and take steps to mitigate them, something he argues is at best "problematic" and at worst "unsustainable."
The reality, he argues, is that underlying network architecture isn't always unreliable or insecure. Broadband and direct-internet access have proven to be robust throughout the pandemic, Bouteyre added. "The COVID-19 crisis and the response of service providers has strongly demonstrated just how reliable and trustworthy underlying infrastructures are."
The Problem With SD-WANMisguided assumptions perpetuated by SD-WAN are increasingly putting pressure on the network, particularly network traffic monitoring, outbound measurement and active probing, and encryption by default, according to Bouteyre.
SD-WAN traffic monitoring can cause packet duplication, which causes higher capacity consumption, and outbound management and active probing exacerbate the problem by generating useless traffic when none is available, he claimed.
Telemetry is useful when there is a known problem on the network, but these functions are consuming network resources the rest of the time as well, Bouteyre explained. "The most capacity hungry solutions can consume up to 50 GB over two weeks in a single WAN interface."
In addition to chewing up bandwidth, this telemetry may also necessitate more powerful and subsequently more expensive appliances, he added.
As such, Bouteyre questions the wisdom of encrypting traffic without considering these unintended consequences. "As a result, even on a secured and reliable network such as MPLS, the overall frame size and once again bandwidth required is needlessly increased," he wrote.
The FixProviding an SD-WAN platform that is easy to deploy, doesn't double up on existing features, can support a hybrid WAN environment, and is properly optimized, is the best solution to these challenges, according to Bouteyre.
To address the first challenge, Ekinops' SD-WAN Xpress platform can be deployed as a VNF on CPE hardware. This allows enterprises to migrate to SD-WAN when they are ready without the need for another appliance.
Moreover, since Ekinops' Xpress can enabled from the company's OneOS6 on CPE hardware, it can take advantage of existing functionality baked into the operating system, eliminating traffic caused by duplicated functionality. This runs counter to all-in-one SD-WAN offerings, which require dedicated hardware and include functionality that may not be required or even desired by customers.
"In many instances, SD-WAN is required only to get a secured link over the internet, but often operators are saddled with considerably more complex solutions than needed, adding complexity, cost, and pressure on networks," Bouteyre wrote.
This criticism isn't unique to Ekinops. Open source SD-WAN vendor flexiWAN and its founder and CEO Amir Zmora has been vocal in his critique of vendor lock in and how it hurts managed service providers and telecommunications partners.
Comments