A wide area network (WAN) is a network that connects an organization’s locations, such as offices, stores, plants, data centers and cloud environments, across cities, countries or continents. Unlike a local area network (LAN), which stays within one building or campus, a WAN runs over services from carriers or over the internet, or both. It is what lets a branch reach the ERP system in the data center, a call reach a colleague in another office and a site reach cloud applications through the company’s security controls.
At a glance
- A WAN connects separate locations; a LAN connects devices within one location.
- It can run over private carrier services, such as MPLS and Ethernet, over internet links with encrypted tunnels, over cellular, or a mix.
- Many modern business WANs combine an underlay of circuits with an overlay, such as SD-WAN, that steers traffic across them.
- Design choices, such as where traffic goes to the internet and how sites connect to the cloud, shape performance and security as much as bandwidth does.
- It can be run in-house, bought as a managed service or split between the two.
What problem it solves
Once an organization has more than one location, its people and systems need to reach each other. Point-of-sale terminals need the payment system, clinics need the records system, plants need production planning, and everyone needs email, voice and cloud apps. A WAN provides those connections in a controlled way: it decides which sites can talk to which, how traffic is protected in transit, which applications get priority and what happens when a link fails.
Without a planned WAN, sites end up with a patchwork of internet connections, ad hoc VPNs and different carriers, which is hard to secure, troubleshoot and pay for.
How it works
Edge devices. Each site has a router, firewall or SD-WAN appliance that connects the local network to the WAN and applies routing and security policy.
Transport (underlay). The circuits that carry traffic between sites. Options include MPLS and other private carrier services, dedicated internet access, broadband, fixed wireless, cellular (wireless WAN over LTE or 5G) and satellite. Many sites have two different links for resilience. See overlay and underlay networks.
Overlay and routing. Over the circuits, sites are joined by private carrier routing, encrypted VPN tunnels or an SD-WAN overlay that chooses the best path for each application based on measured performance.
Topology. Sites can connect in a hub-and-spoke pattern through a central data center, in a full or partial mesh, or through regional hubs. See network topology.
Internet and cloud access. Traffic to the internet can be sent back through a central site for inspection, or sent out locally at each branch through local internet breakout, usually with cloud-delivered security such as SASE. Direct connections to cloud providers are increasingly part of WAN design.
Operations. Someone has to monitor links, manage configurations, work with carriers on faults and plan capacity, whether that is your team, a provider or both.
When it matters for buyers
- When opening, closing or acquiring sites. Each change raises questions about circuits, lead times and how the site joins the network.
- When carrier contracts renew. A renewal is the natural time to reconsider the mix of private and internet transport.
- When applications move to the cloud. Routing all traffic through a central data center can add delay for cloud apps; WAN design should reflect where applications now live.
- When users complain about calls or apps between sites. Latency, packet loss and congested links are WAN problems, and WAN optimization or better path selection may help.
- When going international. Distance and local carrier markets make WAN design harder; see international private backbone.
Our SD-WAN and managed network services overviews cover common ways businesses buy and run a WAN.
Questions to ask vendors
- Which transport options are available at each of our sites, and what are the lead times?
- What do you commit to in the SLA (availability, time to repair, performance), and does it cover the whole path or only your network?
- How does failover work, and how long does it take?
- Where does our internet and SaaS traffic exit, and how is it secured?
- How do our sites connect to our cloud providers?
- What is managed by you and what remains our responsibility?
- What visibility will we have into link performance and incidents?
- How are new sites added, and what does a move or disconnect cost?
How it differs from SD-WAN
A WAN is the network itself: the connections between your sites, whatever they are built from. SD-WAN is a way of building and running that network, using software at each site to combine several links, steer applications over the best one and manage policy from a central console. An SD-WAN is a WAN, but a WAN doesn’t have to use SD-WAN; a traditional MPLS network with routers at each site is also a WAN. A private WAN is the subset built on carrier services kept separate from the internet.
