SD-Branch (software-defined branch) is an approach to branch networking that brings a site’s WAN, security, wired switching and Wi-Fi under common, software-driven management, usually from a single cloud-based console. It extends the ideas of SD-WAN, such as central policy and zero-touch deployment, from the WAN link to the rest of the branch: network switches, wireless access points and the local firewall. What exactly is included depends on the vendor or provider, so the label alone does not tell you which functions are covered.
At a glance
- SD-Branch combines management of SD-WAN, security, switching and Wi-Fi for branch sites, typically in one cloud console.
- It often consolidates devices, for example an SD-WAN appliance with built-in firewall plus switches and access points from the same vendor.
- Zero-touch provisioning lets new sites come online with little or no on-site configuration, depending on the platform.
- It suits organizations with many similar sites and little local IT staff.
- Scope varies by vendor; some include cellular, IoT or security cameras, others only WAN and Wi-Fi.
What problem it solves
A typical branch has accumulated a router, firewall, switches and Wi-Fi, often from different vendors, each with its own management tool, configuration and support contract. Rolling out a new site means configuring each device. Troubleshooting means checking several dashboards, and keeping policy consistent across hundreds of sites becomes hard.
SD-Branch aims to treat the branch as one system. Policies for traffic, security and access are defined centrally and pushed to all sites. New equipment can be shipped to a site, plugged in and configured automatically. Operators see the WAN, wired and wireless health in one place, which shortens troubleshooting for sites with no local IT.
How it works
Edge device. An SD-WAN appliance at the site handles WAN connections, routing and often firewall and other security functions. Some platforms combine these in one box; others use separate devices under common management.
Local network. Switches and access points, often from the same vendor, connect users and devices. Because they are managed with the edge device, a policy such as “put guest Wi-Fi on its own segment and send it straight to the internet” can be set once and applied end to end.
Cloud management. A central console holds configuration templates, monitors devices and collects analytics. Changes are pushed to sites, and firmware updates can be scheduled across the estate.
Zero-touch deployment. Devices are registered to an account before shipping. On site, they connect to the internet, contact the management service and download their configuration, depending on the platform.
Delivery models. SD-Branch can be bought as products you run yourself or as a managed network service, with the provider owning configuration and monitoring.
Our SD-WAN page explains how to evaluate the WAN side of an SD-Branch design.
When it matters for buyers
- Many similar sites. Retail, banking, healthcare clinics and restaurants with dozens or hundreds of locations benefit most from templates and central control.
- Refresh cycles. When branch routers, firewalls and switches reach end of life around the same time, consolidating can simplify the next generation.
- Lean IT teams. If sites have no local staff, unified visibility and zero-touch setup reduce site visits.
- Security changes. If you are moving some security to a cloud service such as SASE, check how SD-Branch devices and cloud security will work together.
Questions to ask vendors
- Which branch functions does your SD-Branch offering manage: WAN, firewall, switching, Wi-Fi, cellular, others?
- Can it manage third-party devices we already own, and with what limits?
- How does zero-touch provisioning work, and what is needed on site?
- What happens at a site if it loses contact with the cloud console?
- How are licenses priced per device, per site or per user, and what happens at renewal?
- Is it available as a managed service, and who handles configuration changes and monitoring?
- How does it integrate with our cloud security or SASE plans?
How it differs from SD-WAN
SD-WAN manages a site’s WAN connections: choosing paths across links such as broadband, DIA, MPLS and cellular, based on application needs. SD-Branch includes SD-WAN but extends the same central management to the branch’s local network and security, such as switches, Wi-Fi and firewall. You can run SD-WAN without SD-Branch; SD-Branch usually assumes SD-WAN is part of the package.
