Network Design & Resilience

MPLS vs SD-WAN: How to Decide, and Why Many Businesses Run Both

MPLS is a private network one carrier runs for you. SD-WAN is software that makes any mix of circuits behave like one. Here is how to choose, and how to migrate without drama.

MPLS is a private network between your sites, run end to end by one carrier, with traffic classes and an SLA that covers performance between locations. SD-WAN is software and a device at each site that builds encrypted tunnels over any circuits you choose, often ordinary internet, and steers each application down the healthiest path. MPLS still suits businesses that need tightly promised performance between fixed sites. SD-WAN usually fits better when most traffic goes to cloud applications, and many companies run a hybrid of the two during, or instead of, a full migration.

This is one of the most common decisions multi-site businesses face at contract renewal. It is often framed as old versus new. The more useful framing is: where does your traffic go, and who do you want to be responsible for getting it there?

What MPLS actually is

MPLS stands for Multiprotocol Label Switching, the technique the carrier uses inside its network to forward your traffic along predetermined paths. What you buy is usually called an MPLS VPN or IP VPN: each site gets an access circuit into the carrier's network, and the carrier keeps your traffic logically separate from every other customer's while connecting all your sites to each other.

Three things define it in practice:

  • One carrier, end to end. The carrier is responsible for the path between your sites. Where it does not reach a site directly, it arranges access through a partner, but it still owns the service.
  • Classes of service. Traffic is marked and queued by priority, so voice and critical applications can be protected when a link is busy.
  • A site-to-site SLA. Latency, jitter and packet delivery between your locations are commonly written into the contract, not just uptime of each access circuit.

MPLS traffic is private, but it is not encrypted by default. Its protection comes from separation inside the carrier's network, which is sufficient for many organisations and not for others.

What SD-WAN is

SD-WAN sits on top of whatever circuits each site has: dedicated fiber, shared fiber, cable, wireless, or MPLS itself. An edge device at every site builds encrypted tunnels to the other sites and to the cloud, measures every path continuously, and sends each application along whichever path currently meets its needs. Policy is set once, centrally, and pushed to every site. If you want the mechanics in plain terms, start with SD-WAN explained; this article focuses on the comparison.

Side by side

MPLSSD-WAN
Who is responsible for the pathOne carrier, end to endYou or your managed provider, over circuits from any carriers
Underlying circuitsThe MPLS carrier's access at each siteAny mix: DIA, shared fiber, cable, wireless, even MPLS
Performance promiseSite-to-site SLA with traffic classesDepends on the circuits; SD-WAN steers around problems rather than promising against them
Cloud and SaaS accessOften routed through a central hub firstDirect from each site to the internet or cloud
EncryptionPrivate, not encrypted by defaultEncrypted tunnels by default
Resilience at a siteUsually one access circuit unless you buy a secondDesigned around two or more circuits per site
Adding a siteOrder an access circuit from the MPLS carrierShip a device; use any circuit available at the building
Making changesTicket to the carrierCentral console, by you or your provider
Carrier choiceOne carrier across the estateBest carrier per building

Why so many businesses moved

MPLS was designed for a world where applications lived in the company's own data center. Every branch connected to the hub, and internet access was usually provided centrally, so all web traffic went to headquarters first and out from there. When applications moved to the cloud, that design started working against users: a branch opening a cloud application sends the request across the MPLS network to headquarters, out to the internet, back to headquarters, and back to the branch. The detour adds delay and loads the hub's internet circuit with traffic that never needed to go there.

SD-WAN lets each site send cloud traffic straight out through its own internet circuit, while still sending internal traffic through encrypted tunnels. It also lets each site use whatever carrier serves that building best, instead of whatever one carrier can reach everywhere.

Where MPLS still earns its place

  • Heavy site-to-site real-time traffic. If your critical applications run between your own locations, such as a central system that branches depend on minute by minute, a contractual site-to-site performance promise has real value.
  • Sites with poor internet options. Where the only internet available at a site is weak, a carrier-managed private circuit can be the steadier choice.
  • Contractual or regulatory expectations. Some clients and auditors specify private transport. Check whether encrypted SD-WAN over internet satisfies the requirement before assuming it does not.
  • No appetite to manage anything. MPLS puts one carrier on the hook for the whole network. A managed SD-WAN service can offer something similar, but you need to choose one deliberately.

For private point-to-point links between a few sites, a Layer 2 service such as Ethernet transport is another option worth pricing alongside both.

Hybrid: the common middle ground

Many businesses do not choose one. They keep MPLS at the sites where it matters most, add an internet circuit at every site, and run SD-WAN across all of it. SD-WAN then treats MPLS as one more path: it can send latency-sensitive internal traffic over MPLS while it is healthy, send cloud traffic directly to the internet, and fail over to the internet path if the MPLS circuit goes down. Over time, as contracts end, the MPLS share can shrink or disappear. The hybrid is also the safest way to migrate, because nothing is switched off until its replacement has been proven.

A worked example

Hypothetical company, sites and measurements, invented to show the reasoning. They are not a real client or carrier data.

A professional services firm has eight offices on MPLS, with headquarters in Chicago and branches including Austin and Miami. All internet traffic leaves through a DIA circuit at headquarters. Staff in the branches complain that their cloud office suite is slow, and headquarters' internet circuit is busy all day.

The IT lead measures a branch in Austin. Going directly to the cloud provider's nearest region from a test internet connection takes a hypothetical 20 ms round trip. Going the existing way, over MPLS to Chicago and then out, takes a hypothetical 55 ms, and the Chicago circuit is congested at peak. The detour, not the branch circuit, is the problem.

The firm's MPLS contracts end on different dates over the next 18 months. The plan:

  1. Deploy SD-WAN devices at all eight sites, running over the existing MPLS plus a new local internet circuit at each branch.
  2. Send cloud and internet traffic directly out of each branch; keep internal traffic on MPLS for now.
  3. As each branch's MPLS term ends, replace it with a second internet circuit from a different carrier, verified as physically diverse where possible.
  4. Keep MPLS at headquarters and the data center until the last branch has moved, then review whether it is still needed.

The branches get faster cloud access in the first month, and no site ever depends on an untested design. Whether the monthly bill goes down depends on the circuits available at each address, which is exactly what the bids at each renewal will show.

Security changes with SD-WAN

With MPLS and central internet access, security was concentrated at headquarters: one firewall, one place to inspect traffic. Once each site breaks out to the internet directly, each site needs the same protection. That can be a firewall at every site, security built into the SD-WAN device, or a cloud-delivered security service that inspects traffic wherever it enters the internet. Plan this at the same time as the network, not afterwards. Our cybersecurity page covers the options.

Contracts and timing

  • Map every end date first. MPLS estates often have site contracts ending at scattered times. Migrating at each end date avoids early termination fees.
  • Check for minimum spend commitments. Some MPLS agreements commit you to a total monthly spend across the estate, not just per site. Removing sites early can trigger a shortfall charge.
  • Order internet circuits early. A new circuit takes 2–4 weeks in a lit building and 60–90 days where construction is needed. Start well before each MPLS term ends.
  • Plan the addressing. Moving off MPLS can change how sites are addressed and routed. Make sure your IT team or provider has a plan before the first cutover.

For the broader discipline of running many sites, see multi-site business internet.

Questions to ask your carrier or provider

  • For MPLS: what does the SLA promise between my sites, per traffic class, and how is it measured?
  • For MPLS: which of my sites are on your own network and which are reached through a partner?
  • For MPLS: is there an estate-wide minimum spend, and what happens if I remove sites?
  • For SD-WAN: who monitors the network, who changes policy, and what are the support hours?
  • For SD-WAN: how does each site's internet traffic get security inspection?
  • For both: can I run them together during migration, and who is responsible when a problem sits between the two?

Price both before you renew

The honest answer to MPLS vs SD-WAN is usually visible only once you price the circuits at each of your actual addresses. We can have Tier 1 carriers bid on MPLS, dedicated and shared circuits at every site, and quote SD-WAN fully managed or as equipment you run, including our managed network option. If your current MPLS contract is already the better deal, we will say so. The carrier pays us, so nothing is marked up, and the quote is free. Send us your site list, call 478-758-8091 or text (347) 870-0965.

// QUESTIONS

Frequently Asked Questions

01What is the main difference between MPLS and SD-WAN?

MPLS is a private network one carrier runs between your sites, with traffic classes and a site-to-site SLA. SD-WAN is software and an edge device at each site that builds encrypted tunnels over any circuits you choose and steers each application down the healthiest path.

02Is MPLS obsolete?

No. It still suits businesses with heavy real-time traffic between their own sites, sites with poor internet options, or clients that require private transport. Many businesses have moved cloud traffic to SD-WAN while keeping MPLS where it still adds value.

03Is SD-WAN cheaper than MPLS?

Often, but not always. SD-WAN lets each site use the best-priced circuit available at its building, while MPLS depends on one carrier's pricing across the estate. The real answer depends on the circuits available at each of your addresses and the SD-WAN licensing or management fees.

04Can I run MPLS and SD-WAN together?

Yes. A hybrid design runs SD-WAN over both MPLS and internet circuits, using MPLS for internal traffic and the internet for cloud traffic. It is also the safest way to migrate, because each site keeps its MPLS circuit until the new design is proven.

05Is MPLS traffic encrypted?

Not by default. MPLS keeps your traffic logically separate from other customers inside the carrier's network. SD-WAN tunnels are encrypted by default.

06How long does an MPLS to SD-WAN migration take?

Usually as long as your MPLS contracts take to end, because migrating each site at its term end avoids early termination fees. New internet circuits take 2 to 4 weeks in lit buildings and 60 to 90 days where construction is needed, so order them well ahead.

// FREE · NO OBLIGATION · SAME-DAY RESPONSE

Want This Priced for Your Address?

Reading is cheap; a real number for your building is better. Pick a time below, or call and we will talk it through.

EMAIL INFO@FIBERXINTERNET.COM · TEXT (347) 870-0965

FIBERX · APPOINTMENT CONSOLE
Book an Appointment

Talk to Phil. Pick a Time.

A quick call with your dedicated agent — internet quotes, AI automation, or both. No obligation, same-day response.

Pick your 30-minute slot ALL TIMES ET
or call 478-758-8091

REQUEST GOES STRAIGHT TO PHIL · SAME-DAY CONFIRMATION