Overlay and underlay networks are two layers of the same network. The underlay is the physical network and transport that actually carries packets: circuits such as broadband, fiber internet, MPLS or cellular, plus the routers and switches that connect them. The overlay is a virtual network built on top of the underlay, usually by wrapping traffic in tunnels between endpoints, so that sites and applications see one logical network regardless of which circuits sit underneath. SD-WAN is the most familiar example of an overlay for most buyers.
At a glance
- The underlay is the circuits and hardware that move packets; the overlay is a virtual network running across them.
- Overlays usually use tunnels, such as IPsec or GRE, to connect sites over the underlay.
- An overlay can combine different circuit types and carriers into one network with central policy.
- Overlay quality is limited by the underlay: it can steer around problems but cannot remove them from a circuit.
- Responsibility is often split, with one party running the overlay and each carrier running its circuit.
What problem it solves
Traditional enterprise wide area networks tied the logical network to the circuits that carried it. An MPLS network, for example, was both the transport and the private routing between sites, from one carrier. Adding a site, a second carrier or a cheaper circuit type meant changes in that carrier’s network.
Separating overlay from underlay breaks that tie. The overlay defines how sites connect, which traffic goes where and what is encrypted, while the underlay can be whatever circuits are available and affordable at each location. A business can add broadband next to an MPLS circuit, swap carriers at one site or add cellular backup without redesigning the network that users and applications see. The same idea is used inside data centers and clouds, where virtual networks run on top of a shared physical fabric.
How it works
The underlay. At each site, one or more circuits connect to the internet or a private network: dedicated internet access, broadband, MPLS, fixed wireless or cellular. The underlay provides basic reachability between the overlay endpoints, typically with ordinary IP routing.
Tunnels. Edge devices at each site build tunnels to each other, or to cloud gateways, across the underlay. Each packet in the overlay is wrapped in an outer header addressed to the far end of the tunnel and often encrypted. The underlay only sees the outer packet.
Control and policy. In SD-WAN and similar services, a controller tells the edge devices which tunnels to build, which applications use which paths, and how to treat traffic. Many platforms measure each underlay path for loss, latency and jitter and move traffic when a path degrades.
Inside data centers and clouds. The same model appears in software-defined networking (SDN) and cloud virtual networks, where tenants get isolated overlay networks on shared physical infrastructure, often using encapsulations such as VXLAN.
To see how overlay and underlay are combined into a managed service, see our SD-WAN solution page.
When it matters for buyers
- Buying SD-WAN. Budget and plan for the underlay, not just the overlay. Circuit choice, carrier diversity and bandwidth at each site set the ceiling on performance.
- Troubleshooting. When an application is slow, the first question is whether the problem is in the overlay (policy, device, tunnel) or the underlay (a circuit or carrier).
- Choosing a managed service. Decide whether one provider will own both layers, as in some network as a service (NaaS) offers, or whether you will manage carriers separately.
- Replacing MPLS. Moving from MPLS to an internet-based overlay shifts quality from a carrier’s contractual commitments toward software that manages several circuits, so check what each circuit still commits to.
Questions to ask vendors
- Which underlay circuits do you recommend at each site, and are they from different carriers or paths?
- Will you manage the underlay circuits, or only the overlay?
- How does the overlay detect a degraded path, and how quickly does it move traffic?
- What tunnel overhead should we expect, and how do you handle packet size?
- How do you show whether a problem is in the overlay or a specific circuit?
- When a carrier circuit fails, who opens and tracks the ticket with that carrier?
How it differs from SD-WAN
Overlay and underlay describe an architecture; SD-WAN is a product category that uses it. An SD-WAN builds and manages an overlay across a site’s underlay circuits, adding central policy, application-aware path selection and monitoring. Other things are overlays too, including site-to-site VPNs, GRE tunnels and cloud virtual networks. Understanding the two layers helps when evaluating SD-WAN, because many problems blamed on the SD-WAN product turn out to be in the underlay circuits it runs on.
