A few years back, a typical enterprise’s most essential applications were hosted in the company’s private datacenter and the network was engineered to pass as much traffic as efficiently as possible to/from that one location. Unbeknownst to most organizations that assumption has ceased being true. Your email, CRM, HR systems, file storage and dozens more tools are now SaaS applications hosted somewhere on the public internet — the old network design that was predicated on routing everything back to one location fails at performance where before it facilitated it.

The way SD-WAN was built to solve exactly this mismatch is covered in the section on how SD-WAN works with cloud apps, which explains how intelligent routing adapts to a world where the applications employees rely on daily rarely sit within the company’s own walls anymore.

The Problem With Backhauling Cloud Traffic

Suppose an employee from any branch office using a cloud-basedCRM tool. Normally in a traditional-wide area network, that traffic does not have to go directly into the servers of CRM providers. Instead, it heads first to the main data centre of the company and goes through the security stack there before heading out to the Internet toward its real endpoint destination. When the vast majority of applications were residing in the same data center, then this “backhauling” made sense, however adds real measurable latency when the employee actually needs to communicate to and consume a resource that is already thousands of miles away from where they are.

You multiply this by the hundreds of SaaS tools an average employee now interacts with in one day, you can quickly see that the performance cost adds up. Video calls lag. File uploads crawl. Your employees do notice, and the IT fields complaints about application performance that have little to do with the applications themselves and everything to do with how traffic is routed to reach them.

laptops
Photo by freestocks on Unsplash

Local Breakout Changes the Path

SD-WAN solves this by allowing branch locations to send internet-bound traffic directly over the internet, avoiding the need to route that internet-facing traffic through a central hub first. Also sometimes referred to as local internet breakout, that means an employee request for a cloud application can take the shortest reasonable path rather than taking an indirect and far too long detour.

This functionality relies on an SD-WAN platform’s ability to identify which application is generating a particular traffic flow, because not all traffic should go that way. So sensitive internal data may still need to be routed through central inspection, but traffic bound for a known trusted SaaS platform may very well go directly and expeditiously if the local branch itself has robust enough security controls to inspect and protect that traffic locally.

Application-Aware Routing in Practice

Intelligent is achieved through application-aware routing, where the SD-WAN platform continuously monitors the performance of each transport type at each location and selects the optimal path for a given app based on current conditions. For example, if one broadband connection experiences packet loss, traffic destined for a critical resource can automatically reroute over the other link with no user at the branch seeing any difference.

That is highly relevant to the sort of SaaS tools that have become woven into everyday life. The difference between a dropped video call and a file that takes longer to sync back to its cloud location is huge, yet treating all traffic the same ignores this distinction. Application-aware routing ensures that a network can prioritize based on what is actually needed by the people using it.

Why SaaS Providers Design for This Reality Too

And the direction of the new cloud-first infrastructure shift runs both ways. Just as networking has had to evolve to where applications live, so too are SaaS providers now faced with the need to develop their own infrastructure while anticipating enterprise-grade reliability and security requirements from day one. Highlights of what growing SaaS companies require to succeed. Enterprise readiness for SaaS platforms explains that vendors that are selling into larger customers need to offer explicit uptime guarantees, encryption practices that can be audited by IT teams and sufficient control for internal administrators to hand sensitive data over to a third-party platform without worry.

This matters because it might change how organizations use SD-WAN and cloud application access together. Network design that optimizes delivery to SaaS tools requires those tools themselves to meet minimum security and reliability standards that can be achieved quickly.

Security Cannot Be an Afterthought

The branch office sends traffic straight to the Internet instead of a centralized security stack Only works if that branch can exert proper local controls. Otherwise, a quicker route to cloud app will leave a lighter security defense, and that runs counter to much of the point.

That is tied into the greater movement towards protecting resources by identity and context rather than fixing things that are inside of a perimeter. The guidance from the federal government on this shift, zero trust architecture for enterprises, describes how enterprise trends toward remote users and cloud-based assets sitting outside a traditional network boundary require security models built around protecting individual resources as opposed to defending a perimeter that no longer encloses all of what matters.

Frequently Asked Questions

Does that mean no more security inspection over branch traffic in local internet breakout?

No. Even with these well-designed deployments, security inspection is still required at the branch (either via an integrated firewall or a cloud-delivered service), not something that can be bypassed entirely.

How does SD-WAN know which cloud applications get priority and route them accordingly?

Most of them maintain a continuously updated database of the applications they support and their traffic characteristics, so administrators can enforce policies that prioritize latency-sensitive tools such as video conferencing and allow less time-critical traffic to take a back seat.

Does this approach apply only to large enterprises with multiple offices?

This is no – organizations with just a few locations or even a large remote workforce going to the same SaaS tools still benefit from the same principles of smart routing and local enforcement of security.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.