Back to Blog

SD-WAN yes, but not everywhere: when it pays off and when it's overkill

Multi-site SD-WAN
When it pays off and when it's overkill

SD-WAN has become the default answer to "I have several sites". In 2023, Gartner predicted that by this year 70% of enterprises would have it deployed. We deploy and operate it — and even so, more than once our recommendation has been "you don't need this". Because SD-WAN is an excellent answer to a specific problem. If you don't have that problem, what you're buying isn't an upgrade: it's one more layer to maintain.

What SD-WAN actually solves (no brochure)

Strip away the marketing and SD-WAN does three things. One: it builds a mesh of tunnels between your sites on top of any transport — fibre, a second fibre from another carrier, 4G/5G — and treats them as one resource. Two: it decides per application, in real time, which path each flow takes, measuring latency, jitter and loss on every link; if the primary line degrades, voice fails over to the other one without anyone raising a ticket. Three: it manages everything from a central orchestrator — one policy, and a new site provisions itself when you plug in the box.

The historical push was economic: replacing or complementing carrier MPLS lines with plain, cheap Internet. Gartner itself described it this way: MPLS, the backbone of enterprise networks for over two decades, is being augmented and often displaced by Internet transport; its forecast was that by 2026, 45% of enterprise locations would use only Internet for their WAN connectivity. If you're coming from paying for MPLS per site, SD-WAN is paying for its own migration. That context matters, because plenty of companies never had MPLS: they came from ordinary fibre and IPsec tunnels. For them, half the sales pitch doesn't apply.

The hype numbers, with the caveat

Gartner's 2023 forecasts showed adoption soaring: from approximately 45% of enterprises with SD-WAN in 2021 to 70% by 2026, with half of new purchases already bundled into single-vendor SASE offerings by 2025 — SD-WAN plus cloud security, all in one. Two caveats before mapping those numbers onto your company. First: Gartner looks at the enterprise market; the fact that seven out of ten multinationals with dozens of sites have it says nothing about whether it suits a company with three. Second: "has it deployed" doesn't mean "is getting value from it". An SD-WAN mesh over a single line per site does exactly what a plain old tunnel does, only with a subscription license.

When we would deploy it

  • 1.Enough sites that touching them one by one is a project. The orchestrator's value grows with every site: change the policy once and it reaches all of them. With many sites — or frequent openings and closures, the classic retail and franchise case — zero-touch provisioning stops being a convenience and becomes the difference between opening in days or in weeks.
  • 2.Two real transports per site and applications that suffer. IP voice, remote desktops, video calls: traffic that jitter and loss actually hurt. There, real-time per-application steering does something a static tunnel can't: use whichever path is good right now without dropping the call.
  • 3.Nobody on staff who wants to live inside the network. If there's no in-house network team, a single console with the whole topology and per-line metrics is an honest operational argument — as long as someone actually looks at it. An orchestrator with no owner is an expensive dashboard.

When NOT to: the three cases we run into most

  • Two or three stable sites with good fibre. WireGuard tunnels between sites, clean routing, done. We use WireGuard and BGP daily on our own network and on customers': it's boring, you can understand all of it, and when it breaks it gets fixed with standard knowledge, not a vendor support ticket. Boring, in networking, is a compliment.
  • One line per site. SD-WAN spreads traffic across paths; it doesn't conjure up the second path. If the site has a single fibre, resilience comes from contracting the second transport — another carrier's fibre, or 4G/5G — not from the acronym. It's the same principle we covered with anti-DDoS and the access link: no local software saves a cable that has nothing left to give. First the line, then — if needed — the intelligence to spread the load.
  • Buying it "for security". SD-WAN encrypts the transport between sites, and that's fine — but your people's access security is a different conversation: identity, device and context on every access, whoever connects from wherever. We covered it this very week with the DNS hijacking on hotel Wi-Fi: the mesh between your sites does not protect the laptop sitting in room 507 of a hotel. That's what Zero Trust is for, with or without SD-WAN.

The costs that never show up in the demo

The first is the obvious one: the per-site subscription license, renewed for as long as the network exists. What used to be a depreciable box becomes a fee forever; the five-year math must include licenses, appliance refresh and vendor support, not just year-one pricing. The second is subtler: the orchestrator becomes a critical dependency — on one more piece of software and on a vendor, with its end-of-life cycles and licensing changes. In a fast-consolidating market (remember: half of new purchases already bundled into single-vendor SASE), marrying the wrong platform is paid for in years of migration.

And the third is the one we run into most: the complexity doesn't disappear, it relocates. Tunnels that "manage themselves" manage themselves until the day they don't — and on that day someone has to understand what's underneath: which line is degrading, which carrier has the problem, why the failover didn't switch. We monitor every transport separately, with Zabbix and SmokePing, precisely because the vendor console tells you what the overlay decided, but not always the underlay's uncomfortable truth. SD-WAN without visibility into the transport below is driving while looking only at the satnav.

The five questions before you sign

  • 1.How many sites do you have today and how many will you open or close within two years? If the answer is "three, and the same three", the provisioning argument is worth little.
  • 2.Are there two real transports at every site — or is the second line still "in the plan"? Without a second path, the software has nothing to choose between.
  • 3.Which specific application suffers today, and have you measured it? "The network is slow" is not a metric. Latency, jitter and loss per line, for a week, and then let's talk solutions.
  • 4.Who operates the orchestrator — and the transport underneath — on a Saturday at three in the morning? If the answer is "the vendor, I suppose", you already know what you're buying.
  • 5.Does the five-year math include licenses, hardware refresh and support — compared against the boring alternative of two lines and well-built tunnels? If nobody has shown you that comparison, ask for it.

Where we stand

We are an operator with our own network — BGP, transit, peering, with a public looking glass at lg.everywan.com — and we deploy multi-site SD-WAN when the case calls for it. We have also said "don't deploy it", because we sell no boxes and no licenses: if your case is solved with two lines, WireGuard tunnels and a well-designed network, that is exactly what we will recommend. A good network is not the one wearing the fashionable acronym; it's the one your team — or ours — understands end to end when it breaks.

Sources (verified): Gartner forecasts (70% of enterprises with SD-WAN by 2026 vs ~45% in 2021; 45% of enterprise locations Internet-only by 2026; 50% of new purchases inside single-vendor SASE by 2025 vs 10% in 2022; MPLS augmented and often displaced by Internet transport) as collected in the IEEE ComSoc Technology Blog analysis (Mar 14, 2023). The operational experience (WireGuard, BGP, per-transport monitoring) is our own.

SD-WAN, or two lines and well-built tunnels?

At everyWAN we design and operate multi-site SD-WAN — and we will also tell you when you don't need it, because we sell nobody's licenses. If you want the honest comparison for your sites, prior measurement included, let's talk.

Talk to everyWAN

Tags:

Share:

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN