Documentation

SD-WAN · Guides

Security & segmentation

SD-WAN security features — encrypted site-to-site fabric, network segmentation to separate corporate, guest, and OT traffic, and integrated edge security (firewall, IPS, secure web gateway).

SD-WAN isn't just faster connectivity — it's a place to enforce security at every site. Traffic between sites is encrypted by default, segments keep different kinds of traffic apart, and the edge can run security services locally — integrated SASE security at the edge rather than a separate security stack per branch.

Encrypted fabric

Every site connects to the intSignal fabric over an encrypted overlay. Site-to-site traffic is protected in transit automatically — you don't build or maintain per-site tunnels by hand; the central configuration does it.

Segmentation

Segments (VRFs) keep traffic classes logically separated across the whole WAN:

SegmentTypical use
CorporateEmployee devices and internal apps.
GuestVisitor Wi-Fi, isolated from corporate.
OT / IoTCameras, sensors, industrial controllers.
PCI / regulatedCard-processing or other scoped systems.

Define segments

In SD-WAN → Segmentation, create the segments your business needs and map VLANs or interfaces at each site to them.

Set inter-segment rules

By default segments can't talk to each other. Add explicit allow rules only where a segment genuinely needs to reach another (for example, an app server from corporate).

Apply per-segment policy

Give each segment its own steering and QoS treatment — guest traffic on cheap links, OT traffic tightly controlled.

Edge security services

The edge can enforce security locally so branches break out to the internet safely instead of backhauling everything to one chokepoint:

  • Next-gen firewall — stateful policy at each site.
  • IPS — intrusion prevention on branch traffic.
  • Secure web gateway / DNS security — safe local internet breakout for SaaS.
  • Zero-trust access (ZTNA)least-privilege access to applications instead of flat network access.

This is the SASE model: networking and security converge at the edge. Where you run the Managed SOC, edge security telemetry feeds detections automatically.

Segmentation limits blast radius

If a guest or IoT device is compromised, segmentation keeps it off corporate and regulated systems. Combined with the encrypted fabric, it means a single breach at one site can't roam the WAN.

Need a hand with SD-WAN?Talk to our team →