What Is a Private WAN?

Also called: Private wide area network

Related problems: Site-to-site traffic over the internet is unpredictable for voice and critical apps; Need predictable performance and separation between offices and data centers; Our MPLS contract is up for renewal and we don't know whether to keep it; Auditors or customers ask how traffic between our sites is kept off the public internet

A private WAN is a wide area network that connects an organization’s sites, such as offices, data centers and cloud on-ramps, over carrier circuits or private services kept separate from the public internet. Traffic between sites travels across the carrier’s network, logically or physically isolated from other customers, rather than across the open internet. Common building blocks include MPLS, Ethernet private lines, VPLS and wavelengths. Private WANs are chosen when predictable performance, separation from internet traffic or end-to-end service commitments matter more than the lowest price per Mbps.

At a glance

  • A private WAN carries site-to-site traffic over carrier services separated from the public internet.
  • It can be built with MPLS, Ethernet private lines, VPLS, wavelengths or a provider’s private backbone.
  • Carriers often offer committed rates, traffic classes and end-to-end SLAs, depending on the service.
  • Separation is not the same as encryption: many private WAN services do not encrypt traffic by default.
  • Many organizations now combine private circuits with internet links under SD-WAN.

What problem it solves

Connecting sites over the public internet works well for many applications, but the path between two offices crosses several networks that no single provider controls. Latency, jitter and packet loss can vary through the day, and when something goes wrong, no one owns the whole path.

A private WAN puts site-to-site traffic onto a network one carrier, or a small set of carriers under one contract, engineers and manages. That can give more predictable performance for voice, video and transaction systems, separation from internet threats, and an SLA that covers the path between sites rather than only each site’s access link. It can also help organizations that must show regulators or customers how sensitive traffic is kept apart from the internet.

How it works

Access. Each site connects to the carrier’s network over an access circuit, usually fiber, sometimes Ethernet over copper or fixed wireless. Off-net sites may use another carrier’s last mile.

Service type. The carrier then joins the sites using one or more private services:

  • MPLS IP VPNs route traffic between many sites at layer 3, often with classes of service for voice and critical data.
  • Ethernet private lines give point-to-point layer 2 connections between two sites.
  • VPLS makes multiple sites appear to share one LAN segment.
  • Wavelengths or dark fiber connect large sites, such as data centers, at very high capacity.
  • An international private backbone links regions across countries.

Separation. Customer traffic is kept apart using virtual routing tables, VLANs or dedicated circuits, depending on the service. This separation is logical on most shared carrier networks; it keeps your routes and traffic apart from other customers but is generally not encryption.

Commitments. Private WAN contracts commonly specify committed rates per site, and some include latency, jitter and packet-loss targets between sites. What is measured, and between which points, varies by carrier.

Hybrid designs. SD-WAN can run across private circuits and internet links together, steering each application to the best path. Many organizations keep a private WAN at data centers and major offices while using internet links at smaller sites.

To compare private WAN, SD-WAN and hybrid designs across your sites, see our Private Networking solution page.

When it matters for buyers

  • Renewing an MPLS contract. Compare keeping it, shrinking it to core sites, or moving to SD-WAN over internet.
  • Expanding internationally. Performance across long distances and multiple countries is where private options often earn their cost.
  • Running latency-sensitive applications. Voice, video, trading or manufacturing systems may need tighter performance than internet paths offer.
  • Meeting customer or regulatory requirements. Some contracts or frameworks ask how traffic between sites is protected; separation and encryption answers both need to be documented.
  • Connecting data centers and cloud. Private links to cloud on-ramps can reduce reliance on the internet for heavy traffic.

Questions to ask vendors

  • Which private service types do you propose for each site, and why?
  • Which sites are on-net, and which rely on another carrier’s access?
  • What committed rate, traffic classes and SLA apply between sites, and how are they measured?
  • Is traffic encrypted on your network, or should we encrypt it ourselves?
  • How do you handle diversity and failover for critical sites?
  • Can the private WAN connect to our SD-WAN, cloud providers and data centers?
  • What are the terms for adding, moving or removing sites during the contract?

How it differs from a wide area network (WAN)

A wide area network is any network that connects sites across distance, whether over private carrier services, the public internet or both. A private WAN is the subset built on carrier services kept separate from the internet. An SD-WAN running over broadband is a WAN but not a private WAN; an MPLS network is both.

Frequently Asked Questions

Is a private WAN more secure than a VPN over the internet?
It keeps traffic off the public internet and logically separated from other customers, which reduces exposure. It does not encrypt traffic by default on most services, so many organizations still encrypt sensitive data, and a VPN over the internet can also be well secured. The right choice depends on your requirements and risk appetite.
Is MPLS the same as a private WAN?
MPLS is one of the most common ways to build a private WAN, but not the only one. Ethernet private lines, VPLS, wavelengths and private backbones can also form a private WAN. Private WAN describes the outcome; MPLS is one technology for getting there.
Does SD-WAN replace a private WAN?
Sometimes. Many organizations have moved some or all sites from MPLS to SD-WAN over internet links. Others keep private circuits at key sites and run SD-WAN across both private and internet links. The decision depends on how much predictability your applications need and what each option costs at your sites.
Why do private WAN services cost more than internet?
Carriers typically engineer private services with traffic classes, committed rates and end-to-end SLAs across their own network, and pricing often reflects distance and site count. Internet bandwidth is sold in a more competitive market. Prices vary widely by location, so compare quotes for your actual sites.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.