What Is SDN (Software-Defined Networking)?

Also called: Software-defined network

Related problems: Network changes take weeks because every device is configured by hand; Configurations drift between sites and nobody knows the true state; Hard to automate the network alongside cloud and server changes; Vendors all claim to be "software-defined" and we can't compare them

Software-defined networking (SDN) is an approach to building and running networks in which the decisions about how traffic should flow are made by centralized software, separate from the devices that actually forward the traffic. Instead of configuring each switch or router individually, administrators set policy in a controller, which programs the network devices accordingly. SDN is less a single product than an architecture that underpins many modern network products and services.

At a glance

  • SDN logically separates the control plane (deciding where traffic goes) from the data plane (moving the packets), though how strictly varies by product.
  • A central controller or management platform applies policy across many devices at once.
  • Programmable interfaces let the network be automated and integrated with other systems.
  • It is an architecture, not a product: data center fabrics, SD-WAN, cloud networking and NaaS apply it in different ways.
  • How “software-defined” a product really is varies by vendor, so ask what is centrally controlled and what is not.

What problem it solves

Traditional networks are managed device by device. Each switch, router and firewall has its own configuration, often typed in by hand. As networks grow, changes become slow, mistakes creep in, configurations drift between sites and nobody has a single view of how the whole network behaves. Network changes become a bottleneck for projects that otherwise move quickly, such as cloud deployments.

SDN addresses that by moving control into software that sees the whole network. Policy is defined once and pushed everywhere it applies, changes can be automated, and the network can respond to applications and events rather than waiting for manual reconfiguration.

How it works

Control and data planes. In a traditional device, the software that decides where to send traffic and the hardware that forwards it live in the same box. SDN separates them logically: a controller, or a centralized management platform, holds the network-wide view and policy, while devices forward traffic according to the instructions they receive. How strictly this split is implemented differs between products; many keep some local decision-making on each device so the network keeps working if the controller is unreachable.

Interfaces. The controller talks to devices through standard or vendor-specific protocols, and exposes programmable interfaces (APIs) upward so orchestration tools, cloud platforms and scripts can request network changes.

Policy and automation. Administrators describe what they want, such as which groups can talk to each other or which applications get priority, and the controller translates that into device configurations. Templates and automation keep many sites consistent.

Where you see it. SDN principles appear in data center fabrics, in cloud provider networking, in SD-WAN across the wide area network, and in many network as a service (NaaS) platforms. It is often paired with network functions virtualization (NFV), which turns appliances such as firewalls into software.

Operations. Some organizations run SDN platforms themselves; others consume them through a managed network service where the provider operates the controller. Our managed network services page covers how those arrangements compare.

When it matters for buyers

  • Network refresh. Replacing switches, routers or WAN equipment is a natural time to move to centrally managed, software-defined products.
  • Many sites. Organizations with dozens of locations gain the most from template-driven configuration and a single view.
  • Cloud and automation projects. If infrastructure is managed as code, a network with programmable interfaces fits in rather than holding it up.
  • Comparing vendors. “Software-defined” is used broadly in marketing; understanding SDN helps you test the claim.
  • Choosing managed services. Many managed and NaaS offerings run on SDN platforms, which affects what you can see and change yourself.

Questions to ask vendors

  • What exactly is controlled centrally, and what is still configured on individual devices?
  • What happens to traffic forwarding if the controller or cloud management platform is unreachable?
  • Is the controller on-premises, cloud-hosted by you or available both ways, and what licensing does it require?
  • What APIs are available, and which automation and orchestration tools integrate with them?
  • How are configuration changes tested, approved, logged and rolled back?
  • How is administrative access to the controller secured?
  • If we leave, can we export our configuration and policy?

How it differs from SD-WAN

SDN is a broad architectural approach that can apply to any network: data center, campus, cloud or wide area. SD-WAN is a specific product category that applies software-defined control to connecting sites over multiple wide area links, such as broadband, dedicated internet and private circuits, choosing the best path for each application. SD-WAN is often described as an application of SDN principles, but buying SD-WAN does not make the rest of your network software-defined, and an SDN data center fabric does nothing for branch connectivity.

Frequently Asked Questions

Is SDN the same as SD-WAN?
No. SDN is a general approach to building and managing networks with centralized software control. SD-WAN applies similar ideas to one problem, connecting sites over multiple wide area links. SD-WAN is often described as an application of SDN principles.
Is SDN a product I can buy?
Not as a single product. SDN describes an architecture. You buy products and services built on it, such as data center fabrics, SD-WAN, cloud networking or network as a service, and each implements the idea differently.
What is the difference between SDN and NFV?
SDN separates how the network is controlled from how it forwards traffic, putting control in central software. NFV runs network functions such as firewalls and routers as software on general-purpose hardware instead of dedicated appliances. They are often used together but solve different problems.
Does SDN make the network more secure?
It can help, because consistent central policy and automation reduce manual errors and make segmentation easier to apply. It also concentrates control in the controller and its management access, which must be protected carefully.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.