Choosing branch connectivity means balancing application performance, failure recovery, operating effort and cost. Start by mapping where traffic goes: between branches, to a data centre or directly to cloud services. Then identify which applications must continue if a circuit fails.
Site-to-site VPN, MPLS and SD-WAN are not always competing purchases. SD-WAN can use internet and MPLS circuits, and security and routing policies can be applied around a VPN.
Site-to-site VPN
A VPN provides encrypted connectivity between sites over an underlying network. It can be a practical option for a small or relatively simple estate.
Its performance depends on the circuits, devices and configuration. The tunnel itself is not a complete application policy system, but routers and firewalls can add traffic prioritization, routing and automated failover. Avoid comparing a minimally configured VPN with a fully managed SD-WAN service as though the difference is encryption alone.
Document tunnel ownership, addressing, monitoring and how configuration changes reach each site. Complexity depends on topology and tooling, not a fixed number of branches.
MPLS
A carrier MPLS service can provide private connectivity with contractually defined performance measures. Review the actual availability, latency, repair and escalation terms and the physical route into each site.
Cloud traffic does not inherently have to pass through headquarters: internet breakout and cloud connectivity depend on the service and design. Ask the carrier to show the route used by important applications. Also check circuit installation lead times and options for independent backup connectivity.
SD-WAN
SD-WAN adds centralized policy and path selection across available links. Cisco explains how application-aware routing uses loss, latency and jitter measurements to evaluate paths.
That capability requires suitable policies and working alternatives. A backup link that cannot carry the priority applications is not equivalent to a second full-capacity circuit. Test link loss, degradation and restoration, including the effect on existing sessions.
Compare the whole design
| Decision | VPN-based design | Carrier MPLS | SD-WAN |
|---|---|---|---|
| Performance | Depends on underlay and edge policies | Defined by the contracted service | Steering across measured paths |
| Resilience | Requires redundant paths and failover configuration | Depends on access and carrier redundancy | Requires usable alternative links and tested policies |
| Cloud access | Can use local breakout | Depends on topology and service | Can apply application-aware breakout policies |
| Operations | Depends on automation and topology | Shared with the carrier | Central management still needs an operator |
| Cost | Circuits, edge devices and operations | Circuits and contracted service | Underlay, devices, licensing and operations |
A practical selection process
For each site, record critical applications, normal and peak demand, outage impact, available carriers and recovery expectations. Compare proposals against those requirements rather than selecting from a site-count rule.
Ask for a failure demonstration, a monitoring example and a clear support boundary. Include power loss and a degraded link, not just a disconnected cable. Record the observed application recovery time.
Use the business internet SLA and redundancy checklist to compare carrier commitments, independent paths, and failover acceptance tests before choosing the underlying circuits.
Branch links and individual remote access need separate design decisions. Use the ZTNA and VPN comparison when assessing how staff and contractors reach applications.
BustanTech provides Cisco networking and managed services. Contact us to discuss a branch assessment covering paths, policies and operational ownership.