Enterprise WAN

Classification

(aka resistance to structural change)

NOTE: This classification applies to specific transformational depths (from seed boundaries). SOS Classifications cannot be compared across different depths.

So a “resilient structure” classification for astronomical bodies cannot be compared to one for human immunity series.

Enduring Forms

A mature Enterprise WAN can survive individual circuit failures, router replacements and changes to individual offices because traffic can often take another path. But unlike a global cloud backbone, much of its structure is deliberately software-controlled and can be reorganised over months rather than years.

Type of boundary

Understanding the boundary

Environmental context

An Enterprise WAN exists inside the technological and organisational environment of one company.

Its job is to connect geographically separated parts of that organisation, such as: branch offices, headquarters, data centres, factories, cloud environments and sometimes remote sites.

The physical connections may be supplied by many outside companies. A business might use private carrier circuits at some locations, ordinary broadband at others and mobile connections as backups. 

Modern enterprise WANs increasingly use SD-WAN, meaning software centrally manages how traffic moves across several possible connection types. Cisco describes SD-WAN as supporting MPLS, Internet broadband and LTE/5G rather than requiring one single transport technology. 

Environmental volatility is medium to high.

Individual Internet connections can fail. Carrier services can be interrupted. Branches open and close. Cloud applications change where company traffic needs to travel. Remote work can move demand away from traditional offices. 

Mechanism for determining boundary

A. Origin & Emergence

An Enterprise WAN begins with separate local networks.

A company might have one office in Mumbai, another in London and another in Singapore. Each office can have its own local network. Those local networks do not become an Enterprise WAN until the organisation creates controlled communication paths between them.

Imagine an organisation with several buildings. Each building has its own hallways and rooms. The WAN appears when the organisation creates roads, tunnels or transport routes that let those buildings function as parts of one larger estate.

The same idea applies digitally. Once branch networks, data-centre networks and cloud networks can communicate through centrally managed routes, a higher-level boundary emerges: the Enterprise WAN.


B. Distinguishing Mechanism

The main boundary-mechanism is organisation-controlled connectivity between geographically separated networks. The physical infrastructure may belong to telecom companies or cloud providers.What makes it one Enterprise WAN is that the enterprise decides:

which sites belong,
which destinations can communicate,
which paths traffic should prefer,
which security rules apply.

A simplified path might be: Branch Office → Enterprise WAN → Data Centre

or: Branch Office → Enterprise WAN → Cloud Application

or: Branch Office A → Enterprise WAN → Branch Office B

The Enterprise WAN therefore does not require the company to own every cable. It requires the company to maintain a logical network boundary across infrastructure that may be physically owned by several outside providers. 

Inside the boundary

The sites, cloud environments, WAN gateways, routing policies and secure paths that the enterprise treats as parts of its wide-area network.

Outside the boundary

Other organisations’ networks, the unrestricted public Internet, external cloud services not incorporated into the WAN, and carrier infrastructure beyond the enterprise-controlled connections.

The important distinction is therefore partly rule-based rather than physical.


C. Persistence / Stability Logic

A modern Enterprise WAN can remain recognisable even while its underlying connections change.

Suppose a branch normally uses a dedicated business circuit. If that circuit fails, the branch might switch to broadband or 5G. The physical path has changed. But the branch can still remain part of the same Enterprise WAN. 

Think of a company that normally moves staff between offices by train. If the railway closes and employees temporarily use buses, the organisation’s connection between the offices still exists. Modern SD-WAN systems automate some of this path selection. Cisco describes them as choosing among available connections according to network conditions and application priorities. 

Persistence therefore comes from:

Alternative connections: more than one route may exist.

Central policies: replacement links can inherit the same enterprise rules.

Encryption: traffic can remain part of the private enterprise network even when crossing the public Internet.

Replaceable sites and equipment: a branch router can be changed without reconstructing the WAN.

The higher-level boundary is therefore more stable than many of its individual physical connections.


D. Distinctive Differentiators

1. It connects one organisation’s geographically separated networks

Its defining purpose is not serving the public Internet. It exists to connect places and computing environments belonging to one enterprise.


2. The organisation may not own the underlying transport

An enterprise can build one WAN using:

private carrier circuits,
ordinary Internet connections,
5G,
direct cloud connections.

This makes the boundary unusually interesting: the logical network can persist while its physical substrate changes.


3. It is governed by common policies

The enterprise can decide that financial traffic gets priority, that one branch cannot reach another system, or that sensitive traffic must use certain secure paths. So membership alone does not define the WAN. Shared control rules help maintain the boundary.


4. It spans much larger distances than a branch or campus network

A branch network may cover one office. An Enterprise WAN connects networks separated by cities, countries or continents. Its main problem is therefore distance between organisational sites.


Peer Comparison: Private Backbone Network

Enterprise WANs and Private Backbone Networks can look similar because both connect distant locations. The main difference is who owns or controls the transport structure and what scale of infrastructure is being connected.

A cloud provider’s Private Backbone Network is typically a major internal transport system built to connect its own data centres, regions and edge sites. An Enterprise WAN is the organisation’s logical long-distance network, often constructed partly from connectivity purchased from other providers.

Think of:

Private Backbone: a railway company operating its own rail network.

Enterprise WAN: a business arranging reliable transport among its offices using several railway companies, airlines and roads.

The enterprise controls the journey rules without necessarily owning the transport infrastructure.

Associated boundaries: higher scales
(not exhaustive)

Enterprise Network

The Enterprise WAN genuinely contributes to the larger Enterprise Network. The Enterprise Network includes more than the WAN. It may contain:

branch networks,
campus networks,
data-centre networks,
wireless networks,
cloud networks,
remote-access systems.

The WAN is the part that ties geographically separated pieces together.

A useful structural relationship is: Branch Networks + Data-Centre Networks + Cloud Networks + Enterprise WAN → Enterprise Network

Without the WAN, those networks could continue functioning locally, but the enterprise’s larger digital system would fragment into separate islands.


The Organisation’s Digital Infrastructure

At a still higher level, the Enterprise Network contributes to the organisation’s wider digital infrastructure. Employees, business applications, storage systems, identity systems and cloud services rely on the network to communicate. The Enterprise WAN is therefore several layers below the organisation itself, but its structure helps support many of the organisation’s larger information processes.

Associated boundaries: lower scales
(not exhaustive)

WAN Edge Gateway

Each office or data centre usually needs a gateway connecting its local network to the WAN. This may be a physical router or a virtual software system. It decides which traffic should leave the local site and which WAN path it should use. The gateway is the local doorway into the wider Enterprise WAN.


Secure Tunnel

When ordinary Internet connections are used, two enterprise sites can create an encrypted tunnel between them. A tunnel is not a physical cable. It is a protected communication relationship carried across another network. Think of placing a locked shipping container onto a public freight train.

The railway carries it, but outsiders using the railway are not automatically allowed to open what is inside. 

Carrier Circuit

Some Enterprise WANs also use dedicated connections supplied by telecom carriers. One traditional example is MPLS, a carrier networking technology often used to create predictable connections among company sites. These circuits provide one possible physical transport underneath the wider Enterprise WAN.


WAN Control System

Modern SD-WANs often include central software that distributes routing and security policies across many sites. Instead of configuring each branch completely independently, administrators can define rules centrally.

This control layer is particularly important because it helps many separate physical connections behave as one coherent enterprise boundary.

Understanding interactions

Most commonly interacting boundaries
at similar scales (not exhaustive)

A. Most Important Interacting Boundaries

Branch Networks

Branch networks send traffic into the Enterprise WAN whenever employees or machines need to communicate with resources outside their local site. The WAN determines where that traffic goes and through which path. A branch therefore both depends on and generates demand for the WAN.


Data-Centre Networks

Enterprise applications and databases may reside in private data centres. Branch traffic can cross the WAN to reach those systems, while responses move back toward branches. Changes in where applications are hosted can therefore substantially change WAN traffic patterns.


Cloud Provider Networks

Modern companies increasingly place applications and data in public clouds. The Enterprise WAN may connect branches directly to cloud environments or route traffic toward cloud-based security and networking services.

 

Carrier and Internet Networks

The Enterprise WAN often depends physically on outside networks. Telecom carriers may provide MPLS or private circuits, while ordinary ISPs provide broadband paths. These outside networks can therefore alter the WAN’s available paths even though they are not themselves inside the enterprise boundary.

Mechanism for common interactions
(not exhaustive)

Branch Networks ↔ Enterprise WAN

The interaction occurs at the branch WAN gateway. Traffic leaving the local office reaches this gateway, which applies enterprise routing and security rules before placing it onto an available WAN path.

The branch network therefore hands traffic from a local organisational boundary into a larger geographic one.


Data-Centre Networks ↔ Enterprise WAN

A data-centre gateway performs a similar role. Traffic arriving from distant offices enters the local data-centre network through routing and security equipment.

Traffic leaving the data centre is passed back toward the WAN. This resembles a national road system connecting to the streets inside a large industrial complex.

The two networks operate at different scales but meet at controlled gateways.


Cloud Provider Networks ↔ Enterprise WAN

Cloud environments can be connected through encrypted Internet tunnels, dedicated cloud connections or WAN services provided through cloud networks. This has changed Enterprise WAN architecture significantly. Older WANs often directed branch traffic back through a company data centre.

Modern designs may allow a branch to reach a nearby cloud or SaaS service directly. Cisco describes this shift as local Internet breakout, which avoids unnecessarily sending cloud traffic through a distant central data centre. Cisco


Carrier and Internet Networks ↔ Enterprise WAN

This interaction happens through physical or virtual transport connections. A carrier may provide a private MPLS circuit. An ISP may provide ordinary Internet access. A mobile network might provide 5G backup. The Enterprise WAN then builds its own routing and security relationships over those outside transport networks.

This produces an unusual boundary relationship: the Enterprise WAN may be structurally dependent on infrastructure that remains outside its own organisational boundary.

Other interesting notes

  • The Enterprise WAN can exist without owning its roads. Its identity comes from controlled connectivity among enterprise sites, even when several outside carriers provide the physical paths.
  • Its boundary is partly software-made. Encryption, routing policies and membership rules can bind distant offices into one network even though their traffic crosses infrastructure shared with strangers.
  • The WAN turns geographic separation into organisational proximity. Offices thousands of kilometres apart can interact as parts of one enterprise network because the WAN creates persistent paths between them.
  • Modern WANs are becoming less like fixed roads and more like managed choices among roads. The physical route can change repeatedly while the higher-level enterprise relationship stays intact.
Was this article helpful?
YesNo
Close Search Window

Sign up for updates

Loading
↑