This reference describes the settings that shape how an SD-WAN site behaves. Configure them per site or as shared templates in the Network Portal, which is where central SD-WAN policy orchestration applies them to every location at once.
Traffic policies
A policy maps application classes to path preferences and failover behavior.
| Setting | Description |
|---|---|
| App class | Group of applications (voice, video, SaaS, bulk, default) |
| Preferred path | Which transport(s) the class should use |
| Failover | What happens when the preferred path degrades |
| SLA thresholds | Loss/latency/jitter limits that trigger a path switch |
Path selection
The edge continuously measures loss, latency, and jitter on every transport. When a path violates an app class's SLA thresholds, matching traffic moves to a healthy path — mid-session, without dropping connections.
Tip
Set tight SLA thresholds for real-time classes (voice/video) and looser ones for bulk traffic. Over-tight thresholds on bulk traffic cause unnecessary flapping.
Segmentation
Keep traffic types isolated with segments (VLAN-backed):
- Corporate — trusted user and server traffic.
- Guest — internet-only, isolated from corporate.
- OT / IoT — operational devices, tightly restricted.
Inter-segment traffic is denied by default; open only the flows you need.
Quality of service
Within a transport, QoS prioritizes latency-sensitive classes during congestion so a large download cannot starve a voice call.
Change management
- Edit a site directly, or roll changes out via a template applied to many sites.
- Changes are versioned; review history and roll back in the Portal.
- Network and connectivity events are visible to the Managed SOC when SD-WAN telemetry is forwarded.
