Skip to content
Connectivity8 min

MPLS, SD-WAN or hybrid - choosing a WAN for a multi-country enterprise

The MPLS-versus-SD-WAN debate is mostly over, and the answer was "both". What each transport is good at, where SD-WAN overlays fall short on their own, and how to size a hybrid WAN across markets with very different last-mile realities.

DS
Dollu Solutions Team
Solutions Engineering

Start from the traffic, not the technology - Every WAN decision comes down to what the traffic needs and what the last mile can actually deliver at each site. A multi-country enterprise typically has three traffic classes: real-time voice and video that need bounded latency and jitter; business applications, increasingly SaaS, that need reliable throughput to the internet or to a cloud region; and bulk transfers, backups and replication that need capacity but tolerate delay. Map those against your sites, and the WAN architecture tends to design itself. What does not work is picking a technology first and forcing every site through it.

What MPLS still does well - A private MPLS IP-VPN gives you deterministic performance because the carrier controls the path end to end. Class-of-service marking is honoured across the core, latency and jitter are contracted in an SLA, and the network is inherently private, so traffic between sites never touches the public internet. For sites carrying real-time voice or contact-centre traffic, for connectivity into a data centre or a cloud on-ramp, and in countries where consumer broadband is unreliable, MPLS remains the right answer. Its weaknesses are cost per megabit, provisioning lead time, which can be eight to twelve weeks in some markets, and the fact that internet-bound traffic has to be backhauled to a central breakout, which is exactly the wrong shape for SaaS-heavy workloads.

What SD-WAN changes - SD-WAN is an overlay: encrypted tunnels between edge devices, controlled centrally, that can run over any underlay - MPLS, dedicated internet access, broadband, 4G or 5G. The controller measures loss, latency and jitter on each path continuously and steers each application to the best one according to policy. Voice goes over the path with the lowest jitter; a bulk transfer uses whatever has spare capacity; SaaS traffic breaks out locally to the internet rather than hairpinning through headquarters. Failover between paths is sub-second and per-flow. The result is that you can use cheaper transport for most traffic and reserve premium transport for what needs it, and you can bring up a new site on broadband and a 4G dongle in days rather than months.

Where SD-WAN on its own disappoints - An overlay cannot manufacture quality the underlay does not have. If both circuits at a site are consumer broadband from the same exchange, path selection has nothing good to select. Internet-only SD-WAN across long international distances is subject to the public internet's variability, and voice from a site in Southeast Asia to a contact centre in Europe over pure internet will have bad days. Encryption and path monitoring add overhead and complexity, and a poorly configured overlay can make troubleshooting harder rather than easier. Security also has to be designed rather than assumed: local internet breakout at every site means every site needs a firewall policy, which is why SD-WAN and SASE are now sold together.

The hybrid pattern that works - For most multi-country enterprises the practical architecture is a hybrid. Large sites and any site with real-time or regulated traffic get an MPLS or Ethernet private-line circuit plus a dedicated internet access circuit, with SD-WAN steering across both. Medium sites get DIA plus a second, diverse internet circuit, ideally from a different provider or over a different medium. Small sites, pop-ups and stores get broadband plus 4G or 5G as backup. Cloud connectivity comes via private on-ramps from the MPLS core or from a colocation PoP, so traffic to your IaaS regions is predictable. Voice, if you run a contact centre, is either kept on the private path or delivered as SIP over a QoS-managed DIA circuit. Everything is managed from one controller with one policy set.

Regional realities that shape the design - Last-mile availability varies enormously. In much of Western Europe and North America you can get diverse fibre DIA at most business addresses. In India, the Gulf and Southeast Asia, fibre is excellent in metros and patchy elsewhere, and 4G or 5G backup is essential rather than optional. In parts of Africa and Latin America, MPLS may be the only way to get contracted performance at all. Cross-border regulation matters too: some countries restrict encryption or require local breakout for certain traffic, and a global provider with local presence will know which. Design each region on its own terms, then stitch them together over the private core.

Sizing and cost model - Size private circuits for the real-time and cloud-bound traffic that genuinely needs them, not for the whole site. Size internet circuits generously, because bandwidth on DIA is cheap relative to MPLS and SD-WAN will use it. Expect the total WAN bill to fall by a meaningful margin against an all-MPLS design, but do not expect it to fall to the cost of broadband; the savings come from putting the right traffic on the right path, not from removing private connectivity. Factor in the SD-WAN edge devices, the controller or its subscription, and the operational time to run it, or contract a managed service that includes all three.

Migration order - Move the sites where MPLS is most obviously wrong first: small offices with SaaS-heavy usage and no real-time traffic. Bring them onto DIA plus backup with SD-WAN, prove the operational model, then work back towards the large sites, adding SD-WAN over their existing MPLS before touching the circuits themselves. Leave the contact-centre and data-centre sites until last, and expect that they will keep private connectivity indefinitely. A hybrid WAN done this way is less a migration than a rebalancing, and it can be done without a single site outage.