Intent-based networking (IBN) is an approach to running a network in which administrators describe the outcome they want, such as “guest devices can reach the internet but not internal systems” or “voice traffic gets priority at every branch”, and software works out the device configurations needed to achieve it. In many implementations, the system also keeps checking that the network is still delivering that intent and alerts on, or corrects, drift it detects. It builds on network automation and software-defined networking (SDN) ideas.
At a glance
- You define business or policy outcomes; the platform translates them into device configuration.
- Many products continuously verify that the live network matches the stated intent and flag differences.
- Some can remediate specific problems automatically; many deployments keep a human approval step.
- Usually delivered as a vendor’s management platform, often strongest on that vendor’s own equipment.
- Depends on accurate inventory, clean policies and good network data to work well.
What problem it solves
Traditional networks are managed device by device. To change who can reach what, an engineer may need to update switches, firewalls, wireless controllers and routers at many sites, each with its own commands. Mistakes cause outages, and over time configurations drift away from what the security policy or design document says. When something breaks, troubleshooting means pulling data from many devices by hand.
IBN aims to shift the work from “how do I configure each device?” to “what should the network do?”. Policies are expressed once and applied consistently, and in many products checked continuously, so teams spend less time on repetitive changes and can see more quickly when the network isn’t behaving as intended. It can also make it easier to demonstrate to auditors that segmentation and access rules are in place.
How it works
Capture intent. Administrators define desired outcomes in a management console, often through templates, policy groups or business terms such as user roles, applications and sites, rather than device commands.
Translate. The platform turns that intent into configurations for the relevant switches, routers, wireless and security devices, checking for conflicts with existing policy where it can.
Deploy. Changes are pushed automatically, often with staging, validation and rollback. New devices can be brought online with zero-touch provisioning (ZTP) and receive the right policy.
Verify. Telemetry and network monitoring data are compared against the intent. Many platforms model the network to test whether, for example, two segments can actually reach each other, and report mismatches.
Remediate. Depending on the product and settings, the system suggests fixes, opens tickets or applies approved corrections. Some vendors use machine learning, similar to AIOps, to spot anomalies and likely causes.
When it matters for buyers
- When the network spans many sites. Consistent policy across branches is where translation and verification save the most effort.
- When segmentation or compliance must be demonstrated. Continuous verification can support audits of network segmentation rules.
- When refreshing campus, data center or WAN equipment. Intent-based features are often tied to a vendor’s platform and licensing, so they should be part of the selection.
- When choosing managed or as-a-service networking. Providers may use intent-based tools behind the scenes; ask what visibility you get.
Many SD-WAN and managed network offerings include intent-style policy features. Our managed network services overview covers handing day-to-day operations to a provider.
Questions to ask vendors
- Which parts of IBN does your platform do: translation, automated deployment, continuous verification, automatic remediation?
- Which device types and vendors can it manage, and what is limited for third-party equipment?
- How are intents and policies expressed, and can we export them?
- How does the system validate a change before deploying it, and how is rollback handled?
- What triggers automatic remediation, and can we require approval?
- How is it licensed (per device, per site, subscription tier), and what happens to features if the subscription lapses?
- What data does the platform collect from our network, and where is it stored?
How it differs from network automation
Network automation is the broad practice of using software, from simple scripts to orchestration tools, to make network changes and collect data instead of doing it by hand. Automation tells the network what to do step by step. IBN sits on top of automation and changes the starting point: you state the result you want, the system decides the steps, and in many products it keeps checking that the result still holds. An organization can automate heavily without IBN, but IBN can’t work without automation underneath.
