1. Two options, until now

Historically, a multi-site business had two options. Operator MPLS offers guaranteed performance and a private network, but at a high cost, with long lead times and no control over the operator's core network. SD-WAN cuts costs by using Internet links, but only optimises the path over existing links: it is a software layer sitting on top of a network it does not control.

Operator MPLS

  • Guaranteed performance, private network
  • High cost: about 2.9 times that of a business Internet access
  • 60 to 120 days to open a site
  • No control over the core network, which belongs to the operator

SD-WAN

  • Standard Internet links, lower costs
  • Optimises the path among existing links
  • Software layer (overlay) on top of a network it does not control
  • Handles neither voice nor cloud: the second infrastructure remains

Figures: Flex.eu synthesis of public market data (analysts, operators), SDO study, March 2026.

2. What SD-WAN does not do

SD-WAN selects the best path among existing links. It creates no capacity and does not see the operator's core network; it therefore acts neither on end-to-end QoS nor on traffic engineering. It optimises; it does not control.

That is the point of the GPS image: a GPS picks the best route over the roads that exist, but it can neither widen nor maintain them. SD-WAN delivers 20 to 30% of WAN optimisation; it does not remove the links, and it does not touch the backbone that connects them.

3. The third way

sdMPLS is a multi-site network technology in which each customer has its own virtual backbone router, the VRB, at the heart of a virtualised operator infrastructure. The customer keeps complete control of its core network (routing, quality of service, segmentation) as with MPLS, while using standard access links (fibre, xDSL, 4G/5G) as with SD-WAN — links collected directly into the core, off the public Internet. WAN, voice and cloud can run on one and the same core, which removes the usual double infrastructure.

In one sentence: sdMPLS combines the control of MPLS with the agility of SD-WAN in a single solution, at the price of standard access links — and off the public Internet.

4. How it works

The operator's core network is itself virtualised (VXLAN technology), and each customer receives within it its own virtual backbone router, the VRB, which it controls directly.

Four-layer diagram, bottom to top: 1. standard access links (FTTH, FTTO, xDSL, 4G/5G) connect the sites; 2. the SDO core network, virtualised with VXLAN/EVPN, shared and segmented, operated by the operator; 3. one dedicated VRB per customer, run by the customer (routing, QoS, segmentation, traffic engineering), sealed off from the other customers' VRBs; 4. the customer's services, WAN, voice and cloud, on this single core.
Four layers: the standard access links, the shared and segmented SDO core network, one dedicated VRB per customer, and the services (WAN, voice, cloud) running on this single core.

Vocabulary: your backbone, dedicated and under your control

The VRB belongs to the customer; it is shared with no one. It sits on the operator's SDO core network, shared and segmented by VXLAN, just as an MPLS service sits on the operator's backbone.

What about lead times? Delivery of a link depends on the infrastructure operator serving the site: from a few days to a few months depending on the case. A site whose link already exists is connected in a few days, and every change to the network (routing, QoS, segmentation, opening a flow) takes effect instantly from the VRB, where MPLS takes 60 to 120 days and goes back through the operator for every change.

5. A private network, off the public Internet

Standard access links does not mean Internet links. The sites' links (FTTH, FTTO, xDSL, SDSL, 4G/5G) are delivered into the sdMPLS core network through direct private collection gateways between operators, with private APNs for mobile. Traffic between the customer's sites therefore never transits the public Internet or third-party operators.

Internet access goes through a single Internet exit at the core network, via Flex.eu's BGP routers and transit. Several technical models of shared exit behind a firewall are possible, including for the 4G/5G SIM cards issued to employees: they join the company network with the same security policy as the sites.

Just like MPLS, then: a private network with a single, controlled Internet exit. And because the path is controlled from each site's access all the way to the core and the Internet exit, end-to-end QoS can be defended. What varies is the level of commitment specific to each type of access link (dedicated fibre with guaranteed bandwidth or shared fibre), chosen by the customer site by site.

6. What you control, what the operator runs

Customer side: your VRB

  • Routing
  • Quality of service (QoS)
  • Segmentation (VLANs, segments)
  • Traffic engineering
  • Network policy

Operator side: the SDO core

  • Core network operations
  • Infrastructure monitoring
  • Access links
  • Platform upgrades

What the customer controls is its policy; running the core remains the operator's job. And the distributor can operate the VRB on the customer's behalf.

7. A single infrastructure

In most multi-site businesses, three infrastructures coexist: an MPLS network for the WAN, a separate voice platform, and VLANs or a VPN to reach the cloud. With sdMPLS, WAN, telephony and cloud can run on one VXLAN core, through your VRB, for customers who also carry their telephony and hosting on the SDO core; the others keep their existing services and converge only the WAN onto it.

Everything on one core does not mean everything in one basket: the SDO core is built on four core networks, spread over two hosting sites with two cores each, so as to remain redundant and available whatever the failure (99.95% availability, 4-hour guaranteed time to repair (GTR), 24/7, included).

Before / after. On the left, three separate grey columns: an MPLS network for the WAN, a voice platform, VLANs or a VPN for the cloud, each with its own contract, operations and monitoring. On the right, WAN, voice and cloud sit on the customer's VRB, itself carried by the SDO VXLAN/EVPN core network: one contract, one operations team, one monitoring.
Before: three infrastructures, each with its own contract and operations. After: a single VXLAN core, a single architecture to understand and operate, which evolves from the VRB.

8. Why this name

We are sometimes told the term is misleading, since sdMPLS does not use the MPLS protocol. Correct, and deliberate: sdMPLS delivers the capabilities that businesses were looking for in MPLS (a private, controlled core), in a software-defined way. Just as SD-WAN is not a WAN but a software way of doing WAN.

9. The words to talk about it

Four names, four roles. We build awareness of sdMPLS, we sell and install the VRB, we explain with SDO. They are never synonyms.

NameRoleExample of use
Flex.euThe company that designs and operatesFlex.eu, the French operator behind sdMPLS
SDO (Software Defined Operator)The architecture concept: an operator whose core network is virtualised and software-controlled“The SDO approach virtualises the operator backbone”
sdMPLS®The technology and the market category. It is the “inside” label“Multi-site network powered by sdMPLS technology”
VRB (Virtual Router Backbone)The product: the dedicated virtual router the customer controls day to day“You manage your backbone from your VRB”

See the full glossary: backbone, overlay, VXLAN/EVPN, QoS, traffic engineering, FTTH/FTTO, AMO…

10. What next?