What it is, positioning, key use cases
Cisco Catalyst SD-WAN separates the WAN into an overlay fabric that runs on top of any available transport. Branch routers build encrypted tunnels to each other and advertise reachability through the controllers, so the underlying circuit — MPLS, broadband, LTE or 5G — becomes an interchangeable path rather than a design constraint.
Application-aware routing measures loss, latency and jitter on every tunnel with BFD probes and steers traffic onto the path that still meets the SLA for that application. When the primary path degrades, sessions move without waiting for a routing protocol to reconverge.
Policy is authored centrally and pushed to the fabric instead of being configured device by device. Topology, segmentation, traffic engineering and service insertion all become definitions held in SD-WAN Manager and distributed through the control plane.
Transport security is on by default: tunnels are IPsec, control connections are DTLS/TLS, and new devices are authenticated against the Validator before they are allowed to join the fabric.