What Is Internet Breakout?

Related problems: Cloud apps are slow at branches because traffic goes through headquarters first; Headquarters internet link is overloaded by branch traffic; Microsoft 365 and video calls perform badly at remote offices; Not sure how to secure branch internet traffic without backhauling it

Internet breakout is the point where traffic leaves an organization’s private WAN and goes out to the internet. That exit can be centralized, with branches sending internet traffic across the WAN to a headquarters, data center or hub; regional, through a regional hub or a cloud security point of presence; or local, directly at each branch over its own internet connection. Local breakout, sometimes called direct internet breakout, is the shift that came with SD-WAN and SASE designs, because so many business applications now live in the cloud. Most networks use more than one breakout model, chosen by application or destination.

At a glance

  • Breakout is where internet-bound traffic exits the private WAN: centrally, regionally or locally at each branch.
  • Central breakout keeps inspection and logging in one place but adds distance and loads the hub’s links.
  • Local breakout usually cuts latency to cloud apps, but security has to move to the branch or a cloud service.
  • Regional breakout sits between the two, often through a regional hub or a cloud security point of presence.
  • Policies are usually set by application or destination, so different traffic can exit in different places.

What problem it solves

A network that reaches the internet has to decide where that traffic leaves and where it is inspected. Traditional private WANs were built as a hub-and-spoke network: branches connected over MPLS or VPN to a data center, and internet traffic typically went out through the data center’s firewall. That central breakout made sense when most applications lived in that data center and security was easiest to enforce in one place.

Once email, collaboration, CRM and file storage moved to SaaS, central breakout started to hurt. Traffic from a branch to a cloud service travels to headquarters, out to the internet, and back the same way. That adds latency, loads the central internet link with everyone’s traffic, and makes video calls and SaaS apps feel slow at remote sites. Choosing where traffic breaks out, and moving some of it closer to users, addresses that.

How it works

Central breakout. Branches send internet traffic across the WAN to a hub, where a firewall or proxy inspects it before it exits. One security stack and one set of logs cover every site, at the cost of longer paths and heavy load on the hub’s internet links.

Regional breakout. Traffic exits at a hub or security point of presence in each region, such as one per continent. This shortens paths for distant sites while keeping inspection in a limited number of places. Cloud security services that operate many points of presence are a common way to do this.

Local breakout. Each branch has its own internet connection, such as broadband, dedicated internet access or cellular, and the branch device sends selected traffic straight out. A common approach is to break out well-known SaaS and collaboration traffic locally and keep internal traffic on the WAN.

Traffic policy. The branch device, often an SD-WAN edge or firewall, identifies traffic by application, domain or destination address, and policy decides which exit each flow uses.

Security. Wherever traffic exits, it needs inspection. Local and regional designs typically use a branch firewall or forward traffic to a cloud-delivered security service such as a secure web gateway, the model described by security service edge (SSE) and SASE.

Failover. If one exit fails, policy can send traffic to another, for example from a branch link back to a regional or central exit, depending on the design.

For help designing breakout across many sites, see our SD-WAN solution page.

When it matters for buyers

  • Moving to SaaS and cloud collaboration. Performance complaints from branches often trace back to traffic backhauled to a central exit.
  • Replacing MPLS. A redesign is a natural time to decide which traffic exits where and how it is secured.
  • Evaluating SASE or SSE. Cloud security services are largely built to secure regional and local breakout.
  • Compliance. Some regulated traffic may need to stay on controlled paths or exit at specific points; confirm which flows must not break out locally.
  • Headquarters link upgrades. Before buying more central bandwidth, check how much of it carries branch internet traffic.

Questions to ask vendors

  • Where will each type of traffic exit to the internet: centrally, regionally or at the branch, and how do we change that?
  • Where will traffic be inspected at each exit, and what security features apply?
  • How does the branch device identify SaaS applications, and how are those definitions kept current?
  • What happens to traffic if a local link or a regional exit fails?
  • How will logging and reporting work when traffic no longer passes a single central firewall?
  • Are there extra licenses for local breakout, security inspection or cloud security connectors?

How it differs from hub-and-spoke

Hub-and-spoke describes the shape of the WAN: which sites connect to which. Internet breakout describes where internet-bound traffic leaves that WAN. A hub-and-spoke WAN can break out centrally at the hub, regionally, or locally at each branch, and many do a mix, keeping internal and sensitive traffic on hub-and-spoke paths across the private WAN while trusted SaaS traffic exits locally. Central breakout is simpler to secure and log in one place; local breakout usually improves cloud performance but needs security at each site or in the cloud.

Frequently Asked Questions

What is local breakout?
Local breakout, also called direct or local internet breakout, means a branch sends selected internet traffic straight out over its own internet connection instead of carrying it across the WAN to a central or regional exit. It usually shortens the path to cloud applications, but the branch traffic then needs to be secured at the branch or by a cloud security service.
What is the difference between central, regional and local breakout?
Central breakout sends internet traffic from all sites to one or a few hubs, such as a headquarters or data center, before it leaves for the internet. Regional breakout sends it to a nearby regional hub or cloud security point of presence. Local breakout sends it out directly at each branch. Many networks combine them by application.
Is local breakout less secure than central breakout?
It can be if branch traffic simply goes out to the internet with little inspection. Organizations usually pair local breakout with a branch firewall or a cloud security service, so traffic is still inspected under central policy. The security outcome depends on that design, not on where the exit is.
Do I need SD-WAN for local breakout?
No. A branch router or firewall with its own internet connection can break traffic out. SD-WAN makes it easier to manage per-application policies across many sites and to fail over between links and exits.
Is internet breakout the same as dedicated internet access?
No. Breakout describes where traffic leaves for the internet. Dedicated internet access (DIA) is a type of internet circuit. Any breakout point, central, regional or local, can use DIA, broadband or cellular.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.