Blog · Technology · 9 September 2026 · 6 min read

What is a dedicated virtual backbone?

At the heart of sdMPLS® is an object that is new to most network teams: a backbone router the customer controls, in a core network it does not own. This article explains what “dedicated” means here, what it does not mean, and why the distinction matters.

When we present the VRB, Virtual Router Backbone, the first question is almost always the same: “dedicated, meaning what? Are you setting hardware aside for us?” The answer is no, and that is good news. To understand it, we first need to recall what a backbone is, and what the word “dedicated” has meant until now in enterprise networks.

The backbone, or core network

The backbone, or core network, is the central part of the network that links all sites to one another and to the cloud. In a traditional multi-site network, this core belongs to the operator. With MPLS, the customer has a virtual private network inside this core, but controls none of it: routing, QoS, the way flows cross the backbone are defined by the operator, alone. With SD-WAN, the customer controls its edge devices, but the core is invisible to it: no one on the customer side sees the backbone. In both cases, the core is a closed object.

What a virtualised core changes

A core network can now be virtualised. The open standards VXLAN and EVPN make it possible to create, on a shared infrastructure, virtual networks sealed off from one another: VXLAN encapsulates and isolates the flows of each virtual network, EVPN distributes the control plane. This is what lets the core of an SDO (Software Defined Operator) host, for each customer, a routing instance that belongs to it alone. That instance is the VRB.

The VRB runs in the core network, in a virtual machine of the customer's own. It exposes what a network team already knows how to do: routing, QoS, VLANs and segments, traffic engineering. The customer defines its network policy there as it would on a core router it owned, except that the router is virtual, lives at the operator, and is natively connected to the collection of access links, to the voice platform and to hosting.

Dedicated: what it means

sdMPLS is a VRB dedicated to one end customer. The VRB belongs to the customer: it is shared with no one, and the customer alone controls it. No other company sees its routes, its segments or its QoS rules; no change made by another customer can affect its instance. That is the meaning of the word dedicated: a routing instance that belongs to you alone, of which you are the sole administrator, or which you entrust to your partner if you prefer to delegate.

Dedicated: what it does not mean

The VRB sits on the operator's SDO core network, shared and segmented by VXLAN, just as an MPLS service sits on the operator's backbone. The physical equipment, the links between points of presence and the virtualisation platform are shared between customers; it is this sharing that makes it possible to offer backbone performance at the price of standard links. Isolation, for its part, is provided by VXLAN/EVPN segmentation and by the principle of one VRB per customer. So we say “your backbone, dedicated and under your control”, and we do not say that the physical infrastructure is reserved for you, because that would be false, and because it is not what matters.

What matters is the question asked by one of the eighteen points of the consultants' kit: “is the backbone router you propose an instance dedicated to the customer? what is shared and what is the customer's own?” A good answer clearly distinguishes the two levels. An answer that speaks of dedicated infrastructure without specifying what is dedicated (the dedicated VRB) and what is shared and segmented (the core) deserves to be probed, whoever the operator.

Who does what

Virtualising the core does not transfer operations to the customer. What the customer controls is its policy: routing, QoS, segmentation, traffic engineering. Running the core remains the operator's job: infrastructure monitoring, maintenance, access links, platform upgrades. And the distributor can operate the VRB on the customer's behalf, which answers the most frequent objection: “running a backbone is too complex for my team”. The VRB requires nothing a network team does not already practise; and if there is no such team, the partner takes care of it.

Why the distinction matters

It matters for three reasons. For the customer, because it was control of the core, not the protocol, that made MPLS valuable: a dedicated VRB gives that control back, on standard links. For the consultant (AMO), because a tender must describe precisely what it requires (“dedicated virtual backbone router, administrable by the customer”) rather than a catch-all word. For the credibility of the category, finally: a technology that claimed to reserve physical infrastructure for each customer could not keep its cost promise. sdMPLS makes no such claim. It promises a private, controlled core, on a shared and segmented backbone, and that is exactly what it delivers.