Application steering is what makes SD-WAN more than dual internet: the edge knows which application a flow belongs to and sends it over the path that meets that app's needs — not just whichever link is "up." This is the application-aware WAN traffic steering the service is built around.
Identify applications
The edge classifies traffic by application using built-in signatures, plus your own rules:
- Built-in app recognition — common SaaS and real-time apps (voice, video, Microsoft 365, etc.) are recognized out of the box.
- Custom apps — define your own by domain, IP/port, DSCP marking, or VLAN.
- Groups — bundle apps into classes like Real-time, Business-critical, and Bulk so you write a few policies instead of hundreds.
Set steering policies
For each app or class, choose how it should be treated:
| Setting | What it controls |
|---|---|
| Preferred path | Which transport to use first (e.g. fiber for voice). |
| SLA target | Max latency, loss, and jitter the path must meet. |
| On breach | What to do if the path violates the SLA — switch links or replicate the flow. |
| Fallback | The order of backup paths if the preferred one fails. |
Pick the app or class
In the Network Portal, open SD-WAN → Policies → Steering and select an application or group.
Define the SLA
Set the latency/loss/jitter targets the app needs. Voice and video are strict; bulk backup is loose.
Choose the response
Decide whether a breach should move the flow to another link or (for critical real-time traffic) duplicate packets across two links and de-dupe at the far end.
Publish
Push the policy to the affected sites. Changes are versioned — see Change management.
Real-time path switching
The edge measures every transport constantly. When the preferred path breaks an app's SLA — a fiber circuit starts dropping packets, say — the edge moves that app's traffic to a healthier link without dropping the session. A voice call or SaaS session keeps going; users don't reconnect.
Tip
Pair steering with QoS: steering picks the path, QoS decides which traffic gets priority on that path when it's congested. Together they protect real-time apps end to end.
