The MPLS bill disappeared from the branch budget. The branch still needs someone to own its network outage.
You did not replace MPLS with a single new technology. You replaced the carrier that owned the path with a set of contracts that do not. Procurement saw a sixty percent cost reduction. The network team saw forty more vendors.
With MPLS, the contract bundled the circuit, the service level agreement, the network operations center, and the escalation path into one signature. SD-WAN unbundles all four. The overlay vendor can show that a tunnel is down, but the cause may sit with a local internet service provider, a mobile operator, site power, or customer equipment.
When a site goes hard down, the time to resolution now includes figuring out who provides the local copper, finding their support number, and arguing with a tier-one technician who insists their modem is online. The SD-WAN vendor points to the underlay. The ISP points to the enterprise firewall. Nobody wins a ticket that crosses a vendor boundary.
The composite service level agreement does not exist. Each carrier owns its segment. The SD-WAN vendor owns the overlay. The end-to-end path is owned by whoever signed the SD-WAN contract, which is usually you.
Visibility and the underlay
SD-WAN dashboards provide high-definition telemetry. You can see latency, jitter, and packet loss on every link in real time. But visibility is not control. Knowing exactly why a voice call is dropping over a local broadband connection does not give you the power to fix the underlay.
Voice is the application that tells you the truth about your network. Email, file shares, and routine cloud workloads tolerate best-effort transport. Voice and hard real-time applications do not. Averages hide the failures that matter. A site with 99.9 percent uptime and four hours of unusable jitter is worse than a site with 99.5 percent uptime and clean paths.
The dashboard says the site is up and the tunnels are green. The user says they cannot hear anyone. Both are correct. The path-selection engine might be moving voice to a path that pings better but jitters worse, because it measures with ICMP while voice rides UDP. The overlay is not a network. It is a negotiation with whatever the underlay happens to be doing. Software cannot route around a saturated link or a severed cable.
Tiering the estate
The decision is not a blanket choice between MPLS and broadband. It is a site-level calculation based on what an hour of degraded service costs and whether independent underlays actually exist.
Keep a premium circuit—MPLS, dedicated internet access, or enterprise Ethernet—when a hard real-time requirement meets a single or poor underlay, or where the blast radius of an outage is large. Trading floors, large contact centers, and regional manufacturing plants usually justify the premium.
Move to SD-WAN over broadband when the applications tolerate variable performance, outages can be worked around, and two genuinely independent access paths are available.
To decide which sites qualify, check three inputs:
- What applications run at the site and what their actual tolerance for jitter and loss is.
- What underlays are physically available and truly independent.
- What an hour of degraded service costs the business.
If the cost of degradation is high and the physical underlay options are weak, the site keeps a premium circuit.
Physical diversity and cellular capacity
Two ISP invoices do not equal two diverse paths. A cable connection and a fiber connection often share the same utility pole or underground conduit. If they share a single point of failure, you do not have redundancy. You have to audit the physical entrances, local loops, and aggregation points before trusting an active-active broadband design.
Cellular backup is a capacity decision, not just a link decision. A failover test that lasts five minutes tells you little about a full working day on a mobile network. Check the signal at the installed location, the data terms, and whether the applications actually work through carrier-grade NAT. A consumer-grade SIM that throttles after five gigabytes will fail during a prolonged outage, and an antenna mounted inside a metal rack will not provide the throughput required for a branch to operate.
Procurement and the renewal calendar
One MPLS contract renewed every three years. Forty broadband contracts across a dozen countries renew on forty different dates with forty different terms.
The savings of moving to commodity broadband are subsidized by the operational overhead of managing the renewal calendar. If nobody owns that calendar, you will discover the problem via an auto-renewal invoice. You must either insource the telecom management, outsource it to a managed service provider, or pay a broadband aggregator to provide a single bill and support desk. The aggregator tax is the price of getting back the single point of accountability you had with MPLS.
Checking the work
Before trusting the deployment, verify the mechanics of the overlay and the underlay.
- Measure jitter and packet loss under load during the worst hour of the day, not just latency and availability on a quiet Tuesday.
- Test degraded service as well as hard failure. Pulling a cable proves detection of a clean outage. Congestion and intermittent loss reveal whether path-selection thresholds and hold-down timers behave sensibly.
- Recognize that you can mark quality of service on the internet, but no broadband provider is obligated to honor those markings across its network.
- Understand that local internet breakout changes the branch security model. Sending software-as-a-service traffic direct from the branch saves latency and MPLS bandwidth, but it places the branch directly on the public internet.
- Understand that overlay encryption provides confidentiality in transit. It does not provide path privacy or address data residency transit requirements if your compliance team requires the latter.
The hard dollar savings of moving off MPLS are substantial, but they require you to manage the fragmentation you just created.