Guide | How to Implement SD-WAN for Your Organization: A Simple Technical Intro
Learn the fundamentals of SD-WAN implementation, including unified management, application-aware traffic steering, WAN optimization, and integrated security. Explore SD-WAN architecture, overlay and underlay networks, operational efficiency, and cyber security benefits for hybrid environments.

HOW TO IMPLEMENT SD-WAN FOR YOUR ORGANIZATION A SIMPLE TECHNICAL INTRO
UNIFIED SD-WAN AND SECURITY MANAGEMENT Check Point SD-WAN is natively integrated into the firewall and managed directly from SmartConsole starting with R82.20, unifying WAN connectivity, WAN troubleshooting, application-aware traffic steering, and security policy management in a single platform. Network and security teams can activate SD-WAN, map WAN links, define steering rules, and deploy policy from the same familiar console across on-premises, cloud, and hybrid environments.
Benefits of SD-WAN
OPEX Savings
Agility
Improved User Experience
With the ability to manage the network via a software overlay, new networking services can be delivered in a fraction of the time that it would take for an on-site technician to do the same work.
SD-WAN application performance is monitored for changes in latency, jitter and packet loss. When performance falls below an optimal level, traffic is dynamically routed to another link, ensuring users and applications are always connected.
with multiple links to choose from: MPLS, broadband, and wireless, organizations can build higher- performance WANs using lower-cost and commercially available Internet access.
4
BUILDING BLOCKS OF SD-WAN
Unified Management Security and networking are integrated into a single platform, delivered on premises or from the cloud, with unified management of network connectivity and firewall policies through a single console.
Overlay An overlay network provides site-to-site connectivity (e.g. VPN). Options include edge routers, software based white boxes, and a vast array of software-defined WAN (SD-WAN) appliances.
An underlay or breakout network provides a direct site-to-internet connection, and includes transport and circuit types such as Multiprotocol Label Switching (MPLS), broadband internet (e.g. DSL, copper cable and optic fiber), wireless (e.g. 5G) and local Internet service providers (ISPs) and mobile network operators (MNOs).
Underlay
Network Policy Organizations define a policy in software for routing apps, mitigating performance problems associated with latency, jitter, or packet loss to give users an optimal experience at the lowest possible operating costs.
THREE TYPES OF SD-WAN STEERING BEHAVIOR
This connection type represents direct links to the Internet with more than one ISP or MNO.
You can use a Local Breakout for a firewall with two ISP links, or one ISP and a one wireless link. In addition, a remote site with one primary and one backup MNO link.
You can use a Local Breakout for:
Connecting Zoom application traffic over an ISP link with low latency
Connecting backup transfer traffic over a low-cost ISP link with higher latency.
Directly to Internet Local Breakout
User Branch GW HQ GW
LAN
WAN LINK
1 Local Breakout Traffic steering direct-to-internet
5
It is ideal for controlling the best VPN path between VPN peers, for routing internal traffic between the organization’s sites, either from VPN spokes to a central hub (e.g.
Branch firewalls to Headquarters firewall, or Satellitesto Center), or between VPN sites in a mesh topology.
Ideal for routing Internet traffic on VPN spoke sites through the Headquarters over a VPN tunnel.
This connection uses the overlay-based connection from the Branch to the Center, and a Breakout-based connection from the Center to the Internet.
You can use a VPN Overlay for:
Connecting to a Remote Desktop server installed on an internal network behind the Headquarters firewall.
Connecting from an internal network behind a branch firewall to a Remote Desktop server.
From site to site VPN Overlay
User Branch GW HQ GW
LAN WAN LINK
This connection type represents a direct WAN link with encrypted traffic to Headquarters.
2 VPN Overlay Traffic steering from site-to-site
This connection type represents a direct WAN link with encrypted traffic to Headquarters.
6
THREE TYPES OF SD-WAN STEERING BEHAVIOR
Sending some traffic directly over the local Internet link, and other traffic through the Headquarters for better security inspection.
This provides redundancy for the local Internet connection of the VPN spoke site.
For better security inspection, the user prefers to choose backhaul and not go through local breakout.
You can use a Backhaul for:
Via central site to Internet Backhaul
User Branch GW HQ GW
LAN
WAN LINK
WAN LINK
This connection sends traffic from VPN spoke sites to the Internet through a Central VPN hub site.
Backhaul Traffic steering via central site to internet3
7
THREE TYPES OF SD-WAN STEERING BEHAVIOR
Must-Haves for a Secure SD-WA N Solut ion
GETTING STARTED WITH SD-WAN The next pages provide a basic high-level overview of how to deploy Check Point SD-WAN in your organization, including:
Activating your SD-WAN
Setting up your steering policy
Monitoring your network connections
8
CHECK POINT SD-WAN DEPLOYMENT
Configuring the SD-WAN Blade
WAN link mapping: Assign each SD-WAN link to a gateway interface and next hop directly in SmartConsole.
Interface settings: Define download and upload bandwidth, next-hop IPs, and NAT reachability for each link.
QoS activation: Enable QoS to prioritize and shape download/upload traffic for reliable performance.
2
9
Purchased SD-WAN Blade Activation
Turn on the SD-WAN Software Blade for any firewall directly from SmartConsole — no CLI or separate console needed.
Instant readiness
Once activated, the firewall is ready for WAN link mapping, interface settings, and QoS.
Activating SD-WAN blade on the Firewall1
Define the SD-WAN steering Policy
CHECK POINT SD-WAN DEPLOYMENT
Shared policy model
SD-WAN steering sits alongside Access Control, Threat Prevention, and HTTPS Inspection in the same policy package. You can now manage and push SD-WAN steering to selected firewalls from one SmartConsole.
Familiar rule base
Steering rules use the same source, destination, and services/applications columns you already use for security policy.
Application-aware steering
The Steering and Preferred Source columns route each flow to the best WAN link, per rule.
3
10
Steering Policies Customization
CHECK POINT SD-WAN DEPLOYMENT
Fine-tune default steering policies to ensure applications consistently receive the optimal level of service across dynamic network environments.
Steering candidates include the 3 steering behaviors: local breakout, VPN overlay and backhaul.
Criteria include the links and their performance SLAs.
3-A
11
Customize Your Steering SLAs
CHECK POINT SD-WAN DEPLOYMENT
Step 3-B
Define SLAs for Dynamic Auto-Steering
Check Point SD-WAN, with its real-time monitoring of SLA parameters, such as latency, jitter, and packet loss, empowers businesses to intelligently route traffic based on connection quality.
By analyzing these metrics across network links, Check Point SD-WAN selects paths with lower latency, minimal jitter, and minimal packet loss, thereby improving data transmission speed, ensuring reliable performance for time-sensitive applications, and delivering a seamless user experience.
With its dynamic routing capabilities, Check Point SD-WAN optimizes network resources by leveraging multiple connection options, allowing organizations to prioritize critical applications and achieve enhanced application performance.
Aggregate Bandwidth
Ensure the ability to aggregate link capacity utilizing links from multiple service providers. Bandwidth aggregation eliminates the need to designate redundant tunnels that sit idle in active/standby mode until needed.
3-B
12
MONITOR YOUR WIDE AREA NETWORK TRAFFIC
Advanced Analytics
Advanced real-time monitoring and analytics should be easily available on a dedicated dashboard. Look for live monitoring of link SLAs (also called thresholds), analytics on link swaps and overall network health. This provides both an at-a-glance overview with the ability to drill down for more detail, if needed, to maintain branch connectivity.
Monitor Link Health
Traffic should be monitored for latency, jitter or packet loss to enable automated link swapping, switching from one link to another when defined traffic thresholds are exceeded.
Branch-level visiblity with central management
Figure 2: AI-powered monitoring and remediation insights
13
GET STARTED WITH CHECK POINT SD-WAN
If Check Point Firewalls are already deployed, Check Point SD-WAN can be activated on the current appliance. No additional hardware is required.
14
Deploy Check Point SD-WAN anywhere. It is supported on all firewall form factors, from physical appliances and virtual firewalls to cloud-native deployments. Securing distributed locations, connections, and applications should not require a patchwork of SD-WAN and security tools. Check Point SD- WAN is built into the firewall, bringing WAN connectivity, SD-WAN steering, and security policy together in one unified architecture.
Managed directly from SmartConsole, teams can activate SD- WAN, map WAN links, define steering rules, and push policy from the same familiar console, whether managed 100% on- prem or in the cloud.
BUILT-IN SD-WAN Unified Security Management
Check Point SD-WAN is a software blade in Check Point Force Firewalls that unifies the best security with optimized internet and network connectivity.
Deployed at the branch level, it provides comprehensive prevention against zero-day, phishing, and ransomware attacks, while optimizing routing for users and over 10,000 applications.
To ensure uninterrupted web conferencing, the solution monitors internet connectivity for latency, jitter, and packet loss, performing sub-second failover for unstable connections.
For consistent protection and connectivity across users and branch offices, Check Point SD-WAN delivers a complete security and internet access solution (SASE) managed from the Check Point cloud platform.
MEET CHECK POINT SD-WAN
To learn more about Check Point SD-WAN, visit our website.
Or sign up for a demo here.
To explore all our SD-WAN security solutions, visit our webpage.