Skip to content
Network & Connectivity

Managed SD-WAN

An application-aware WAN that steers every session over MPLS, internet or 5G by policy - orchestrated centrally, provisioned zero-touch, secured with integrated SASE and operated for you around the clock.

Managed SD-WAN - Dollu
  • MPLS + internet + 5G

    Transports blended per site

  • Sub-second

    Application path failover

  • 500+

    Deployments delivered

Overview

What is Managed SD-WAN?

Dollu Managed SD-WAN replaces static, circuit-by-circuit WAN design with a software-defined overlay that understands applications. Each site runs an SD-WAN edge - physical or virtual - that identifies traffic by application, measures loss, latency and jitter on every available path in real time and forwards each session over the transport that meets its policy. Voice goes over the path with the lowest jitter, SaaS breaks out locally to the nearest cloud gateway, bulk backup takes whatever is cheapest, and when a path degrades the session moves in well under a second without a user noticing.

The overlay runs over any mix of transports: Dollu MPLS IP-VPN, Dollu DIA, third-party broadband and LTE or 5G, in whichever combination suits each site's cost, resilience and performance requirements. Because policy is central, a retail estate can run 300 stores on dual broadband with 5G backup while head office and data centres keep MPLS, all under one orchestrator, one policy set and one dashboard. Sites are shipped a pre-registered appliance that pulls its configuration from the orchestrator on first boot, so a branch can be live the day the box arrives.

Security is built into the fabric rather than added at the perimeter. Edges provide next-generation firewall, IPS, URL and DNS filtering and segmentation between VLANs and VRFs, and the fabric integrates with cloud security service edge platforms for secure web gateway, CASB and zero-trust access, giving you a SASE architecture without a forklift. Segments for guests, IoT, PoS and corporate traffic stay isolated from the branch to the cloud, and every policy is version-controlled and auditable in the orchestrator.

We are deliberately vendor-agnostic. Depending on your requirements, incumbent estate and commercial preferences we deploy Fortinet Secure SD-WAN, Cisco Catalyst SD-WAN or Meraki, or Versa, and in every case Dollu designs, provisions, monitors and manages the service end to end from a 24×7 NOC, with per-application analytics in the portal so you can see exactly why a session took the path it did.

How it fits together

Hybrid WAN: MPLS, internet and 5G under one SD-WAN policy.

Hybrid WAN: MPLS, internet and 5G under one SD-WAN policy.Application-aware steering across MPLS, internet and wireless underlays · one policy, one PoP, every destinationBRANCH SITEUsers & devicesLAN · Wi-Fi · IoTSD-WAN edgemanaged CPE · app-awareLocal breakouttrusted SaaS directper-path probes: latency · jitter · lossMPLSprivate · SLA-backedDIA / broadbandinternet · IPsec overlay5G / LTEwireless backupDOLLU POPSD-WAN gatewayoverlay terminationSASE / firewallpolicy · inspectionBackbone1.4 Tbps · 40+ PoPsCloud on-rampsAWS · Azure · GCP · SaaSData centre / HQprivate apps · voiceInternetsecure web gatewayVoice and video are pinned to the best-performing path in real time; bulk transfers take the cheapest path that meets policy.Every branch reaches every cloud through the nearest Dollu PoP, so on-ramps and security policy are shared rather than rebuilt per site.
Reading the diagramA branch keeps whichever underlays make sense - MPLS for guaranteed performance, dedicated internet or broadband for capacity, 5G or LTE as wireless backup. The managed SD-WAN edge probes each path continuously and steers traffic per application: voice and video onto the path with the best latency, jitter and loss right now, bulk traffic onto the cheapest path that meets policy. Everything terminates at the nearest Dollu PoP, where the SD-WAN gateway, security stack and backbone give every site the same route to cloud on-ramps, data centres and the internet.
Why Dollu

Why choose Dollu for managed sd-wan.

The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.

  • Right traffic on the right path

    Policy decides that voice takes the lowest-jitter path, Microsoft 365 breaks out locally and backups use the cheapest circuit, so you stop over-buying premium bandwidth for traffic that does not need it.

  • Branches live in days, not months

    Zero-touch provisioning and template-driven configuration mean a new site needs a courier and a broadband line rather than a field engineer and a six-week circuit order.

  • Lower cost per megabit

    Blend broadband and 5G with MPLS where it earns its keep. Customers typically double usable bandwidth at branch sites for the same or lower monthly spend.

  • Security in the fabric, not bolted on

    Firewalling, IPS and segmentation at every edge plus SSE integration give you a SASE architecture from day one, with one policy for branch, home and cloud users.

  • See what your users see

    Per-application, per-path performance and quality-of-experience scores in the portal turn 'the network is slow' into a specific site, circuit and application in seconds.

Capabilities

Capabilities in detail.

Everything included with Managed SD-WAN - the platform features, options and controls you get from day one.

  1. 01

    Application-aware routing

    Deep packet inspection recognises 3,000+ applications; per-application SLA thresholds for loss, latency and jitter drive path selection, with forward error correction and packet duplication for real-time flows.

  2. 02

    Hybrid transport support

    Any combination of Dollu MPLS, Dollu DIA, third-party broadband, LTE and 5G per site, active-active or active-standby, with bandwidth aggregation across links where the vendor platform supports it.

  3. 03

    Zero-touch provisioning

    Appliances are pre-registered to your orchestrator, shipped direct to site and pull their configuration on first connection; branch staff plug in power and WAN, and our NOC confirms the site online.

  4. 04

    Central orchestration and templates

    Site templates by tier, global and regional policy sets, change staging and rollback, role-based access for your team, and full configuration and policy version history.

  5. 05

    Integrated security and SASE

    Next-generation firewall, IPS, URL and DNS filtering, TLS inspection and micro-segmentation on the edge; native integration with cloud SSE platforms for SWG, CASB and ZTNA, managed by Dollu security operations.

  6. 06

    Cloud on-ramp

    Virtual SD-WAN edges in AWS, Azure, Google Cloud and Oracle, direct tunnels to SaaS gateways, and integration with Dollu private cloud connectivity so cloud traffic never traverses head office.

  7. 07

    Analytics and reporting

    Per-application and per-path throughput, loss, latency and jitter, quality-of-experience scores for voice and video, path-selection event logs, and monthly service reports from your service manager.

  8. 08

    Vendor choice

    Fortinet Secure SD-WAN, Cisco Catalyst SD-WAN or Meraki, or Versa Secure SD-WAN, selected with you against feature, security and cost criteria; migration from a legacy platform included in the design.

  9. 09

    Fully managed lifecycle

    Design, staging, deployment, 24×7 monitoring, incident and change management, software upgrades, licence renewals and hardware replacement, all inside one SLA and one monthly invoice.

How it works

How it works.

From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.

  1. Step 01

    Assess

    We inventory your sites, circuits, applications and security controls, capture traffic profiles from your existing WAN and agree the outcomes the new network must deliver.

  2. Step 02

    Design

    Vendor selection, transport mix per site tier, policy model, segmentation and SASE integration are documented in a low-level design that your team signs off.

  3. Step 03

    Pilot

    A handful of representative sites go live on the overlay alongside the existing WAN, so policies, failover behaviour and analytics can be tuned with real traffic.

  4. Step 04

    Roll out

    Appliances ship to sites in waves; zero-touch onboarding, remote validation and cut-over are run by our deployment team to a published schedule.

  5. Step 05

    Operate

    Our 24×7 NOC monitors every edge and path, manages incidents and changes, and reviews performance, policy and cost with you each quarter.

Compare

MPLS, DIA, broadband or 4G/5G.

No single transport suits every site. Most Dollu WAN designs mix them - an SD-WAN overlay stitches the underlays together and steers voice and critical apps onto the best path.

WAN transports compared on SLA, quality of service, cost, lead time and typical fit.
DimensionMPLS / IP-VPNDedicated internet accessBusiness broadband4G / 5G
SLAHighest - end-to-end latency, jitter, packet-loss and availability targetsHigh - availability and repair time on the circuit; the wider internet path is best effortBest effort; consumer-grade repair timesBest effort; dependent on radio coverage and cell load
QoSEnd-to-end classes of service across the Dollu coreDedicated, symmetrical bandwidth; QoS to the network edge onlyContended and asymmetric; no QoS guaranteesShared spectrum; private 5G adds on-site QoS and slicing
Cost positionHighest per MbpsMidLowestLow - per SIM plus data
Lead timeLongest - new fibre and cross-connects; weeks to monthsWeeks; faster where the building is already litDays to weeksDays - hardware ships and activates on power-up
Best forVoice-critical sites, regulated data, hub-and-spoke WANsHead offices, data centres, cloud on-ramps, SIP trunksSmall sites, backup paths, SD-WAN underlayRapid deployment, temporary sites, resilience overlay, IoT and fleets
Use cases

Who uses this and why.

Typical deployments across carriers, enterprises, platforms and contact centres.

  • Retail and quick-service chains

    Hundreds of stores on dual broadband with 5G backup, segmented PoS and guest Wi-Fi, and central policy that a small IT team can actually run.

  • Banking and insurance branches

    Keep MPLS for core banking while offloading video, SaaS and internet to DIA, with encrypted overlays and audit-grade policy history.

  • Manufacturing and logistics

    Plants and depots on the transports available locally, OT segments isolated from IT, and priority for ERP and telemetry over site-to-cloud links.

  • Cloud-first enterprises

    Local breakout to Microsoft 365, Salesforce and other SaaS with direct cloud on-ramps, so traffic no longer trombones through a data centre.

  • Hybrid work and small sites

    Compact edges or software clients for home offices, pop-up locations and clinics that need corporate policy and security without a dedicated circuit.

Specifications

Technical & commercial specifications.

Key parameters at a glance. Ask us for the full service description and SLA document.

PlatformsFortinet Secure SD-WAN; Cisco Catalyst SD-WAN, Meraki; Versa
TransportsMPLS, DIA, broadband, LTE/5G; up to 4 WAN links per edge
Edge form factorsDesktop, 1U rack, ruggedised, virtual (VMware, KVM, cloud)
Throughput50 Mbps to 10+ Gbps encrypted per edge, by model
Application recognition3,000+ applications via DPI and SaaS feeds
FailoverSub-second path switch; FEC and packet duplication
SecurityNGFW, IPS, URL/DNS filtering, TLS inspection, segmentation
SASE integrationSWG, CASB, ZTNA via leading SSE platforms
Availability SLAUp to 99.99% per site with dual transports and dual edges
Support24×7 NOC; P1 response ≤ 15 min; named service manager
Pricing model

How Connectivity is priced.

Circuits carry a monthly recurring charge set by bandwidth, access type and SLA tier; SD-WAN and managed LAN per site. Every site is quoted individually with a lead time.

We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.

Monthly recurring · per circuit
  • MRC by bandwidth, access type and SLA tier
  • Site-by-site quotes with lead times
  • One-time install charge where applicable, quoted up front
  • 12–36 month terms
  • Multi-country consolidation discounts
Billing
Monthly recurring in advance; install charge on delivery; single invoice across countries
Commitment
12–36 months per circuit
Talk to salesActual rates within one business day.
FAQ

Managed SD-WAN - your questions answered.

The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.

Still have a question?

Ask our solutions team

No. SD-WAN is transport-agnostic and many customers keep MPLS at sites where deterministic performance matters, add DIA or broadband for capacity, and let policy decide which path each application uses. Over time you can shrink or retire MPLS where the data shows internet paths are consistently good enough.

Let’s talk

Model your SD-WAN business case.

Give us your site list and current circuit costs and we will return a transport-mix design and three-year cost comparison within a week.

Abstract globe with connected network lines