SD-WAN vs MPLS for multi-site government, PSU and enterprise networks
SD-WAN vs MPLS for multi-site networks in India: how each works, where each fits, hybrid designs, security, and what a WAN tender should specify.
Ahuva Electronic Technologies · Published
Key points
- MPLS is a carrier's private network that forwards traffic on labels along paths the carrier controls. SD-WAN is an overlay that runs across one or more underlying links, including MPLS, broadband and mobile, and chooses a path for each application by policy.
- SD-WAN and MPLS are not strict alternatives. MPLS can be one of the links an SD-WAN runs over, and many multi-site networks use both.
- An MPLS VPN does not encrypt traffic by itself. RFC 4364, the IETF specification for BGP/MPLS IP VPNs, says cryptographic measures must be added if privacy is needed.
- Mplify Alliance (formerly MEF Forum) standard MEF 70.2 defines an SD-WAN service and says it can offer encryption between SD-WAN edges.
- The strongest multi-site design usually has two different physical paths into each important site, from two providers, with SD-WAN steering traffic across them.
What is the difference between SD-WAN and MPLS?
MPLS (Multiprotocol Label Switching) is a forwarding method used inside a carrier's network, and an MPLS VPN is a private network service a carrier sells on top of it. SD-WAN (software-defined wide area network) is a layer that sits on top of whatever links a site has and decides, application by application, which link each flow should use.
So the two answer different questions. MPLS answers 'which private network carries my traffic between sites'. SD-WAN answers 'how should my traffic use all the links I have'. That is why the comparison below is really about a single-carrier private WAN versus a policy-driven overlay across several links.
| MPLS VPN | SD-WAN | |
|---|---|---|
| What it is | A carrier's private IP network | An overlay across one or more links |
| Transport | The carrier's own network | MPLS, broadband, leased line, 4G or 5G |
| Path choice | Set by the carrier's routing | Per application flow, by policy |
| Encryption | Not by itself (RFC 4364) | Can encrypt between edges (MEF 70.2) |
| Performance commitment | Carrier's SLA on the circuit | Depends on the links underneath |
| Internet and cloud | Usually through a central hub | Local internet breakout possible |
| Changes | Raised with the carrier | Central policy, changed in near real time |
How does an MPLS network work?
An MPLS network classifies each packet once, as it enters, and then forwards it on a short label rather than re-reading the full address at every router. The IETF's MPLS architecture, RFC 3031 of January 2001, describes this: the packet is assigned to a forwarding class at the edge, and that class is encoded as a label.
An MPLS VPN, as described in RFC 4364 of February 2006, uses this to keep each customer's routes separate inside a shared carrier backbone. The customer sees a private network between its sites. The carrier runs the core, and can offer classes of service and a service level on each circuit.
The strengths are predictability and simplicity for the customer. The carrier manages the core, traffic between sites does not cross the public internet, and one contract covers all sites. The weaknesses are cost per site, dependence on one carrier's reach to every location, slower changes, and a design built around a central hub rather than direct access to internet and cloud services.
How does SD-WAN work?
SD-WAN places an edge device at each site that builds tunnels over every available link and sends each application's traffic down the path that best meets its policy. MEF 70.2, published by Mplify Alliance in October 2023, defines an SD-WAN service as an overlay network over one or more underlay connectivity services, which recognises application flows and forwards them according to policies.
MEF 70.2 lists the characteristics a buyer can expect. Paths across the underlying links are selected dynamically for each application flow. Policies can set performance goals per flow. Traffic can be blocked by policy. The service can offer encryption between edges. It typically comes with a portal or API that shows network health and lets the owner change policies. The standard also describes internet breakout, where a site reaches the internet directly instead of through a central hub.
The practical gains are resilience and control. A branch with two links keeps working when one fails. Video from a remote site can use the cheaper link while a billing application uses the better one. Policy changes are made once, centrally, instead of site by site.
Should SD-WAN replace MPLS, or run alongside it?
For most multi-site owners the answer is to run SD-WAN across a mix of links, which may still include MPLS for the sites and applications that need it. MEF 70.2 is explicit that an SD-WAN service can run over underlays from providers other than the SD-WAN provider, including private IP services.
The design choice is which sites get which links. Common patterns are below.
- MPLS plus internet: MPLS stays as the primary path for critical traffic, broadband or a leased internet line becomes the second path and carries internet-bound traffic
- Dual internet: two internet links from two different providers, with SD-WAN encryption and policy, where no application needs a carrier-managed private path
- Tiered sites: head office and data centre on dual high-grade links, larger offices on MPLS plus internet, small sites on broadband plus 4G or 5G backup
- Hub and spoke with regional hubs: traffic from small sites goes to a regional hub, which has the higher-grade links to the data centre
Which is more secure, SD-WAN or MPLS?
Neither is secure by default, and they fail in different ways. MPLS keeps traffic inside a carrier's network, but RFC 4364 states that the methods it describes do not by themselves encrypt data or detect tampering, and that cryptographic measures must be applied in addition if this is desired. Traffic is private from other customers, not encrypted.
SD-WAN often runs over the internet, so it must encrypt between edges and be managed carefully. Local internet breakout also means each branch now has its own internet exposure, which needs firewall and web security at the branch or in a cloud service. The combination of SD-WAN and security delivered as one service is often called SASE (secure access service edge). Mplify Alliance publishes a SASE service standard, MEF 117, revised as Mplify 117.1 in June 2025.
Either way, the network should not be treated as a trusted zone. NIST Special Publication 800-207 of August 2020, on zero trust architecture, sets out the principle that no implicit trust is granted to users or devices based on their network location. For a WAN that means segmenting traffic by function, for example keeping CCTV, building systems and office users apart, and authenticating access to applications rather than trusting anything that arrives over the WAN.
What matters most for government, PSU and enterprise WANs in India?
Last-mile diversity usually matters more than the choice of technology. Two links that share the same duct, pole route or exchange will fail together, whatever runs over them. For important sites, the buyer should ask for two providers and confirm the physical routes are different.
Traffic mix is the next question. Surveillance and command-centre projects move large volumes of video from many field sites to one centre, and that traffic is steady rather than bursty. It needs bandwidth sized for the camera count and recording plan, not a generic branch profile. Office applications, video conferencing and citizen services each need their own policy.
Operations decide how well either option works after go-live. An SD-WAN with no one watching its dashboard is only a set of routers. The contract should say who monitors the network, who calls the carriers when a link fails, and how quickly a failed edge device is replaced at a remote site.
What should a WAN tender specify?
A WAN tender should specify outcomes per site class and per application, and leave the bidder to propose the mix of links that meets them.
- Site classes, with required availability and bandwidth for each
- Application classes and their priority, including video, voice, business systems and internet
- Number of links per site class, and a requirement for provider and physical path diversity at critical sites
- Encryption between all sites, whatever the underlying link
- Segmentation between functions such as CCTV, building systems, staff and guests
- Where internet access happens, and what security is applied there
- Central monitoring, reporting, and who owns the relationship with each carrier
- Replacement times for failed edge devices at remote sites
How Ahuva approaches WAN and SD-WAN work
Ahuva's networking scope covers enterprise LAN, WAN and SD-WAN, high-density campus wireless, NAC and monitoring, and fibre backbone. Its OEM authorisations include Cisco for network transport and compute. In 2025 it was empanelled with BSNL as an authorised business partner for IT and network delivery, and with RailTel as an authorised business partner.
Frequently asked questions
- Is SD-WAN cheaper than MPLS?
- It can be, because SD-WAN lets a site use broadband and mobile links alongside or instead of MPLS. The saving depends on how many sites still need premium links and on the cost of the SD-WAN service and its operations.
- Does MPLS encrypt traffic?
- Not by itself. RFC 4364, the IETF specification for BGP/MPLS IP VPNs, keeps customers' routes separate but says encryption must be added separately if privacy is needed.
- Can SD-WAN run over MPLS?
- Yes. MPLS can be one of the underlying links an SD-WAN uses, often as the primary path for critical traffic with an internet link as the second path.
- What is local internet breakout in SD-WAN?
- It means a branch reaches the internet directly over its own link instead of sending traffic to a central hub first. It needs firewall and web security at the branch or in a cloud security service.
- Is there a standard for SD-WAN?
- Yes. MEF 70.2, published by Mplify Alliance (formerly MEF Forum) in October 2023, defines SD-WAN service attributes that a buyer and provider can agree on.
Sources
- RFC 3031: Multiprotocol Label Switching Architecture · Internet Engineering Task Force (IETF)
- RFC 4364: BGP/MPLS IP Virtual Private Networks (VPNs) · Internet Engineering Task Force (IETF)
- MEF 70.2 SD-WAN Service Attributes and Service Framework · Mplify Alliance (formerly MEF Forum)
- SASE service standards · Mplify Alliance (formerly MEF Forum)
- SP 800-207: Zero Trust Architecture · National Institute of Standards and Technology (NIST)
Related
Scoping a system like this? Talk to the team that designs, builds and maintains it.
Contact us