The encrypted site-to-site overlay fabric connects your locations; the topology decides how they reach each other and your apps. intSignal SD-WAN supports the common designs and lets you mix them.
Topologies
| Topology | How it works | Good for |
|---|---|---|
| Hub-and-spoke | Branches connect through a central hub (data center or cloud). | Centralized apps and security. |
| Full mesh | Every site can reach every other directly. | Real-time traffic between sites (voice, video). |
| Regional hubs | Spokes home to a regional hub; hubs interconnect. | Large, geographically spread networks. |
| Dynamic mesh | On-demand site-to-site tunnels form when two branches talk directly. | Mesh benefits without a full-mesh config. |
Add a site
Create the site
In the Network Portal, choose SD-WAN → Sites → Add and name the location, its region, and its role (spoke, hub, or cloud gateway).
Assign transports & segments
Attach the site's transports and map its VLANs to segments.
Ship and provision the edge
Send the edge appliance to the site and bring it online with zero-touch provisioning — no on-site engineer required.
Cloud & data-center gateways
Extend the fabric into the places your apps actually live:
- Cloud on-ramps — deploy a virtual edge in AWS, Azure, or GCP so branches reach cloud workloads over the fabric instead of the open internet.
- Data-center gateway — connect an existing DC as a hub for private apps.
- SaaS breakout — let branches reach SaaS directly and safely via edge security, instead of hair-pinning through a hub.
Tip
Start hub-and-spoke for simplicity, then enable dynamic mesh so two branches that run a lot of voice or video between them form a direct path automatically — you get mesh performance where it matters without managing a full mesh.
