MPLS is a private network between your sites, run end to end by one carrier, with traffic classes and an SLA that covers performance between locations. SD-WAN is software and a device at each site that builds encrypted tunnels over any circuits you choose, often ordinary internet, and steers each application down the healthiest path. MPLS still suits businesses that need tightly promised performance between fixed sites. SD-WAN usually fits better when most traffic goes to cloud applications, and many companies run a hybrid of the two during, or instead of, a full migration.
This is one of the most common decisions multi-site businesses face at contract renewal. It is often framed as old versus new. The more useful framing is: where does your traffic go, and who do you want to be responsible for getting it there?
What MPLS actually is
MPLS stands for Multiprotocol Label Switching, the technique the carrier uses inside its network to forward your traffic along predetermined paths. What you buy is usually called an MPLS VPN or IP VPN: each site gets an access circuit into the carrier's network, and the carrier keeps your traffic logically separate from every other customer's while connecting all your sites to each other.
Three things define it in practice:
- One carrier, end to end. The carrier is responsible for the path between your sites. Where it does not reach a site directly, it arranges access through a partner, but it still owns the service.
- Classes of service. Traffic is marked and queued by priority, so voice and critical applications can be protected when a link is busy.
- A site-to-site SLA. Latency, jitter and packet delivery between your locations are commonly written into the contract, not just uptime of each access circuit.
MPLS traffic is private, but it is not encrypted by default. Its protection comes from separation inside the carrier's network, which is sufficient for many organisations and not for others.
What SD-WAN is
SD-WAN sits on top of whatever circuits each site has: dedicated fiber, shared fiber, cable, wireless, or MPLS itself. An edge device at every site builds encrypted tunnels to the other sites and to the cloud, measures every path continuously, and sends each application along whichever path currently meets its needs. Policy is set once, centrally, and pushed to every site. If you want the mechanics in plain terms, start with SD-WAN explained; this article focuses on the comparison.
Side by side
| MPLS | SD-WAN | |
|---|---|---|
| Who is responsible for the path | One carrier, end to end | You or your managed provider, over circuits from any carriers |
| Underlying circuits | The MPLS carrier's access at each site | Any mix: DIA, shared fiber, cable, wireless, even MPLS |
| Performance promise | Site-to-site SLA with traffic classes | Depends on the circuits; SD-WAN steers around problems rather than promising against them |
| Cloud and SaaS access | Often routed through a central hub first | Direct from each site to the internet or cloud |
| Encryption | Private, not encrypted by default | Encrypted tunnels by default |
| Resilience at a site | Usually one access circuit unless you buy a second | Designed around two or more circuits per site |
| Adding a site | Order an access circuit from the MPLS carrier | Ship a device; use any circuit available at the building |
| Making changes | Ticket to the carrier | Central console, by you or your provider |
| Carrier choice | One carrier across the estate | Best carrier per building |
Why so many businesses moved
MPLS was designed for a world where applications lived in the company's own data center. Every branch connected to the hub, and internet access was usually provided centrally, so all web traffic went to headquarters first and out from there. When applications moved to the cloud, that design started working against users: a branch opening a cloud application sends the request across the MPLS network to headquarters, out to the internet, back to headquarters, and back to the branch. The detour adds delay and loads the hub's internet circuit with traffic that never needed to go there.
SD-WAN lets each site send cloud traffic straight out through its own internet circuit, while still sending internal traffic through encrypted tunnels. It also lets each site use whatever carrier serves that building best, instead of whatever one carrier can reach everywhere.
Where MPLS still earns its place
- Heavy site-to-site real-time traffic. If your critical applications run between your own locations, such as a central system that branches depend on minute by minute, a contractual site-to-site performance promise has real value.
- Sites with poor internet options. Where the only internet available at a site is weak, a carrier-managed private circuit can be the steadier choice.
- Contractual or regulatory expectations. Some clients and auditors specify private transport. Check whether encrypted SD-WAN over internet satisfies the requirement before assuming it does not.
- No appetite to manage anything. MPLS puts one carrier on the hook for the whole network. A managed SD-WAN service can offer something similar, but you need to choose one deliberately.
For private point-to-point links between a few sites, a Layer 2 service such as Ethernet transport is another option worth pricing alongside both.
Hybrid: the common middle ground
Many businesses do not choose one. They keep MPLS at the sites where it matters most, add an internet circuit at every site, and run SD-WAN across all of it. SD-WAN then treats MPLS as one more path: it can send latency-sensitive internal traffic over MPLS while it is healthy, send cloud traffic directly to the internet, and fail over to the internet path if the MPLS circuit goes down. Over time, as contracts end, the MPLS share can shrink or disappear. The hybrid is also the safest way to migrate, because nothing is switched off until its replacement has been proven.
A worked example
Hypothetical company, sites and measurements, invented to show the reasoning. They are not a real client or carrier data.
A professional services firm has eight offices on MPLS, with headquarters in Chicago and branches including Austin and Miami. All internet traffic leaves through a DIA circuit at headquarters. Staff in the branches complain that their cloud office suite is slow, and headquarters' internet circuit is busy all day.
The IT lead measures a branch in Austin. Going directly to the cloud provider's nearest region from a test internet connection takes a hypothetical 20 ms round trip. Going the existing way, over MPLS to Chicago and then out, takes a hypothetical 55 ms, and the Chicago circuit is congested at peak. The detour, not the branch circuit, is the problem.
The firm's MPLS contracts end on different dates over the next 18 months. The plan:
- Deploy SD-WAN devices at all eight sites, running over the existing MPLS plus a new local internet circuit at each branch.
- Send cloud and internet traffic directly out of each branch; keep internal traffic on MPLS for now.
- As each branch's MPLS term ends, replace it with a second internet circuit from a different carrier, verified as physically diverse where possible.
- Keep MPLS at headquarters and the data center until the last branch has moved, then review whether it is still needed.
The branches get faster cloud access in the first month, and no site ever depends on an untested design. Whether the monthly bill goes down depends on the circuits available at each address, which is exactly what the bids at each renewal will show.
Security changes with SD-WAN
With MPLS and central internet access, security was concentrated at headquarters: one firewall, one place to inspect traffic. Once each site breaks out to the internet directly, each site needs the same protection. That can be a firewall at every site, security built into the SD-WAN device, or a cloud-delivered security service that inspects traffic wherever it enters the internet. Plan this at the same time as the network, not afterwards. Our cybersecurity page covers the options.
Contracts and timing
- Map every end date first. MPLS estates often have site contracts ending at scattered times. Migrating at each end date avoids early termination fees.
- Check for minimum spend commitments. Some MPLS agreements commit you to a total monthly spend across the estate, not just per site. Removing sites early can trigger a shortfall charge.
- Order internet circuits early. A new circuit takes 2–4 weeks in a lit building and 60–90 days where construction is needed. Start well before each MPLS term ends.
- Plan the addressing. Moving off MPLS can change how sites are addressed and routed. Make sure your IT team or provider has a plan before the first cutover.
For the broader discipline of running many sites, see multi-site business internet.
Questions to ask your carrier or provider
- For MPLS: what does the SLA promise between my sites, per traffic class, and how is it measured?
- For MPLS: which of my sites are on your own network and which are reached through a partner?
- For MPLS: is there an estate-wide minimum spend, and what happens if I remove sites?
- For SD-WAN: who monitors the network, who changes policy, and what are the support hours?
- For SD-WAN: how does each site's internet traffic get security inspection?
- For both: can I run them together during migration, and who is responsible when a problem sits between the two?
Price both before you renew
The honest answer to MPLS vs SD-WAN is usually visible only once you price the circuits at each of your actual addresses. We can have Tier 1 carriers bid on MPLS, dedicated and shared circuits at every site, and quote SD-WAN fully managed or as equipment you run, including our managed network option. If your current MPLS contract is already the better deal, we will say so. The carrier pays us, so nothing is marked up, and the quote is free. Send us your site list, call 478-758-8091 or text (347) 870-0965.