1. SDO, Software Defined Operator
An SDO (Software Defined Operator) is an operator whose core network is fully virtualised and software-controlled. Where a traditional operator runs a hardware backbone whose behaviour it alone defines, an SDO runs the core functions (routing, switching, segmentation) in a software layer, on standard infrastructure, and can therefore delegate part of them to each customer.
sdMPLS is the technology that follows from this approach: it is the SDO concept turned into a multi-site network offer. The signature of the approach: the operator backbone, virtualised and controlled by the customer.
Virtualising the operator core is not a laboratory idea: Orange, AT&T and Verizon already have disaggregated equipment (commodity hardware and open network software) in production in their networks (Flex.eu synthesis of public data, SDO study, March 2026).
2. The VXLAN/EVPN core
Flex.eu's SDO core network is a single backbone, built on the VXLAN and EVPN standards, that carries at the same time:
- the cloud: virtual machines and hosting, delivered directly into the core;
- operator collection: the access links of all customer sites;
- the voice platform: SIP trunks and telephony services.
The architecture is spine-leaf: every access device (leaf) is connected to all the core devices (spine). Capacity is added by horizontal extension, with no central component whose capacity would cap the whole. This is what sets sdMPLS apart from a central SD-WAN orchestrator, which generally tops out at 1,000 to 2,000 sites.
VXLAN encapsulates the frames of each virtual network and seals them off from one another; EVPN distributes the control plane. Together, they let the shared core host one virtual network, and one VRB, per customer.
3. The VRB, Virtual Router Backbone
The VRB is the virtual backbone router dedicated to the customer. It runs in the SDO core, in a virtual machine of the customer's own, and is the point from which the customer controls its network. It is dedicated: it is shared with no one, and the customer alone controls it (or delegates that control to its partner).
What the VRB exposes to the customer
- Routing: tables, policies, announcements towards the sites and towards the cloud
- QoS: classes of service and flow prioritisation, with end-to-end QoS from each site's access all the way to the core and the Internet exit
- VLANs and segments: segmentation of the customer's network, in the core and not only at the edges
- Traffic engineering: choosing the paths that flows take through the backbone
The VRB exposes what a network team already knows how to do. What the customer controls is its policy; running the core (monitoring, maintenance, platform upgrades, access links) remains the operator's job.
Wording to remember: sdMPLS is a VRB dedicated to one end customer. The VRB sits on the operator's SDO core network, shared and segmented by VXLAN, just as an MPLS service sits on the operator's backbone. So we say “your backbone, dedicated and under your control”.
4. Open standards
sdMPLS is built on open, documented standards, not on proprietary technology:
- VXLAN (RFC 7348) for the encapsulation and isolation of virtual networks;
- EVPN (BGP EVPN, RFC 7432 and following) for the control plane;
- FRR (FRRouting) for the routing protocols (BGP, OSPF, etc.).
Consequence for the customer: the configuration of its VRB is expressed in standard formats, can be exported and reused elsewhere. The customer is locked neither into a vendor control plane (the SD-WAN case) nor into hardware and long contracts (the operator MPLS case).
5. Performance
More than 3 million packets per second per VM: real backbone performance, not that of a software overlay. Public benchmark in preparation.
This performance comes from the architecture of the virtualised leaf: the switching functions are integrated into the hypervisor and accelerated by smart network cards (SmartNICs), in direct communication with the spines. Each VRB runs in its own VM and benefits from this data path.
As a matter of prudence, Flex.eu publishes no quantified comparison with other software routers until the public, reproducible benchmark is available. The method (packet size, test conditions) will be published with the results.
6. Access links
Sites connect to the SDO core over standard access links, at market prices, chosen site by site according to eligibility and criticality:
FTTH
Shared fibre, for branches and small sites.
FTTO
Dedicated business fibre with guaranteed bandwidth, for head offices and critical sites.
xDSL
ADSL or SDSL, where fibre is not yet available.
4G / 5G
Backup, temporary sites, provisional start-up before the fixed link is delivered.
Mobile access relies on Flex.eu's MVNO offer on the Bouygues Telecom network; integration of the Orange network is planned for mid-2027. The link is an access to the core: changing a link's technology (xDSL to fibre, for example) does not change the customer's configuration in its VRB.
Collected directly into the core, off the public Internet
These links are not Internet links. They are delivered into the sdMPLS core network through direct private collection gateways between operators, with private APNs for mobile: traffic between the customer's sites never transits the public Internet or third-party operators. Internet access goes through a single Internet exit at the core network, via Flex.eu's BGP routers and transit, according to several technical models of shared exit behind a firewall — including for the 4G/5G SIM cards issued to employees, which join the company network with the same security policy as the sites. Just like MPLS, then: a private network with a single, controlled Internet exit.
Consequence: since the path is controlled from each site's access all the way to the core and the Internet exit, end-to-end QoS can be defended. What remains variable is the level of commitment specific to each type of link (FTTO with guaranteed bandwidth, shared FTTH), chosen by the customer site by site.
7. Security and segmentation
The SDO core is shared between customers; its segmentation relies on VXLAN/EVPN, which creates sealed virtual networks, and on the principle of one VRB per customer: no routing instance is shared. The customer can itself segment its own network inside its VRB.
The customer's network is off the public Internet: traffic between its sites never transits the public Internet, and Internet access goes through a single exit at the core, behind a firewall, with the same security policy for the sites and for the employees' 4G/5G SIM cards (see Access links).
The SDO core and the VRB configurations are hosted in France. The core is deployed as a geo-cluster on two hosting sites, each with two core networks, i.e. four cores, so as to remain redundant and available whatever the failure: 99.95% availability and a 4-hour guaranteed time to repair (GTR), 24/7, included. These commitments cover the core network; at the access, the type of link chosen site by site (dedicated fibre with guaranteed bandwidth or shared fibre) sets the level of commitment.
8. Market benchmarks
Context figures: Flex.eu synthesis of public market data (analysts, operators), SDO study, March 2026. These are sourced benchmarks, to be distinguished from Flex.eu's own estimates.
Source: Flex.eu synthesis of public market data (analysts, operators), SDO study, March 2026. Market: global MPLS $27.7bn (2025), SD-WAN $9.3bn; French MPLS IP VPN market $1.88bn (2023).
The SDO core in figures
Source: Flex.eu, September 2026.
Lead times. Delivery of an access link depends on the infrastructure operator serving the site: from a few days to a few months depending on the case. A site whose link already exists is connected in a few days. And every change to the network (routing, QoS, segmentation, opening a flow) takes effect instantly from the VRB: that is where the difference lies with the 60 to 120 days of MPLS, where every change goes back through the operator.