A CIO who receives a multi-site network proposal today almost always hears the same sentence: “SD-WAN will let you move off MPLS”. The promise is attractive, and the market figures seem to bear it out. Yet in many businesses, SD-WAN has been added to the existing network rather than replacing it. To understand why, you have to look at what each technology does, and above all at what it does not do.
What MPLS delivers, and what it costs
Operator MPLS offers guaranteed performance and a private network. That is why businesses adopted it: voice goes before backups, sites see one another without transiting the public Internet, and the operator makes contractual commitments. But this comfort has three prices. Cost, first: MPLS costs on average 2.9 times more than a business Internet access. Lead time, next: opening a site takes 60 to 120 days. Control, finally: the core network belongs to the operator, and every change to routing or quality of service goes through a request. The number of MPLS connections is declining by 24% a year; not because the need has gone away, but because the price of that need has become hard to defend.
What SD-WAN really does
SD-WAN is a software layer sitting on top of your links. At each site, a device watches the available links (fibre, xDSL, 4G) and picks, for each flow, the best path at that moment. This is useful: costly MPLS links can be replaced with standard Internet accesses, gaining 20 to 30% of WAN optimisation. But you have to be precise about what this mechanism touches. SD-WAN selects the best path among existing links. It creates no capacity, does not see the operator's core network, and acts neither on end-to-end QoS nor on traffic engineering. It optimises; it does not control.
The image we use is the GPS. SD-WAN is a GPS that picks the best route over existing roads, but can neither widen nor maintain them. When the public Internet is congested between two sites, the GPS can suggest another link; it cannot decide what happens in the backbone it crosses. It is an overlay: a logical network built on top of a physical network it does not control.
Why the two coexist
This is why so many businesses keep MPLS under their SD-WAN, at least for critical sites: the overlay did not give them back the control of the core they had with MPLS; it gave them flexibility at the edges. And there is a second reason, often forgotten in comparisons: SD-WAN only handles the WAN. Telephony stays on its own platform; hosting and cloud are still reached through VLANs or a VPN. The double infrastructure that MPLS already imposed (one network for WAN and voice, another chain for the cloud) has not disappeared; it has simply changed shape.
So the choice offered to businesses looks like this: keep control and pay dearly, or pay less and give up control. It is a false dilemma, because it rests on an implicit assumption: that the operator's core network is a closed object the customer will never be able to control.
The third way: making the core controllable
That assumption is no longer true. An operator's core network can itself be virtualised, with the open standards VXLAN and EVPN, and carved into sealed virtual networks. This is the SDO approach, Software Defined Operator: an operator whose core network is fully virtualised and software-controlled. In this core, each customer receives its own virtual backbone router, the VRB, which it controls directly: routing, quality of service, segmentation, traffic engineering.
This is what we call sdMPLS. The customer gets what MPLS gave it (a private, controlled core, with real traffic engineering) and what SD-WAN promised it (standard, low-cost links, brought into service in a few days), in a single infrastructure that carries the WAN, telephony and hosting at the same time. To return to the analogy: MPLS is a private motorway you rent at a high price; SD-WAN, a GPS; sdMPLS, your own road network, whose traffic plan you decide, built on standard roads.
And if you already have an SD-WAN?
There is no need to remove it. The SD-WAN stays; it only selects a path. sdMPLS replaces what sits underneath. And it removes the second infrastructure (cloud, voice) that SD-WAN does not handle. The useful question is no longer “MPLS or SD-WAN?”, but: which core is my network built on, and who controls it?