BFSI
Consolidating MPLS and LTE/5G Under Managed SD-WAN with SASE
How a BFSI client unified fragmented MPLS and LTE/5G links under a managed SD-WAN with SASE, cutting downtime and accelerating branch rollout.
The position we inherited
The network had grown one branch at a time. Each new location arrived with whatever circuit was available that quarter, so the estate settled into a mix of MPLS for core sites, LTE/5G for smaller or temporary offices, and a handful of broadband links that nobody could fully account for. Every link was managed separately, with its own provider ticket queue and its own configuration.
Routing decisions were made by hand. The network team steered traffic per site, and adding a branch meant a change window, a fresh set of static routes, and a slow cycle of testing against production. There was no single view of link health, and no consistent security posture across the footprint. Some sites inspected traffic at the edge, some backhauled to the data center, and several fell between the two.
The business pressure was straightforward. Transaction volumes were climbing, the cost of idle primary circuits showed up in every quarterly review, and the risk of an outage during banking hours had stopped being a theoretical concern.
What we designed
We kept the transport the organization already paid for and put a managed SD-WAN overlay above it, then folded security into the same policy fabric instead of bolting it on.
Underlay is deliberately mixed. MPLS is retained where it earns its price: latency-sensitive core flows between data centers and the primary transaction path. LTE/5G is promoted to an actively used, application-aware path rather than a standby, which is what makes the total cost work. Broadband links carry bulk traffic such as software distribution, backup windows, and non-critical web access.
The overlay runs an application-aware policy model. Traffic is classified once, then steered by measured loss, latency, and jitter, with per-application rules that send voice and transaction traffic down the healthiest path while an email client can ride whichever link is cheapest. Forward error correction and packet duplication are applied selectively to the flows that genuinely need them, because applying them to everything consumes the bandwidth the design is meant to conserve. BGP handles reachability between sites, and route summarization keeps the control plane small enough that convergence stays predictable during a failover.
Security moved into a zero-trust posture. Every branch identity is authenticated before it reaches an application, so network location no longer implies trust. Secure web gateway and data loss prevention policies are enforced at the edge with the same rules regardless of transport, and workloads are segmented so a compromised kiosk network cannot reach core banking. For a regulated institution, the useful part is that these controls are defined in policy and evidenced in logs, which is what makes audit and compliance reporting a query rather than a project. Retention and data residency follow the regulator’s requirements, with traffic flows documented per application.
How we migrated
Nothing was ripped out on day one. We built a site template, then applied it location by location, starting with the branch carrying the least critical traffic. Legacy MPLS remained in place as a path throughout, so a site could be moved back by changing policy rather than by re-cabling.
The change process was rebuilt at the same time. Templates replaced per-site configuration, rollback became a policy revert instead of a maintenance window, and onboarding a new branch was reduced to a documented sequence that local staff could follow.
Operations
The overlay is run as a managed service with 24x7 monitoring, defined escalation paths, and firmware and policy lifecycle handled for us. Fault isolation starts with the overlay rather than the carrier, because the first useful question is which path failed and what the policy did about it. Underlay circuit faults are then raised with the right provider with the evidence already attached, which removes the usual round of tickets where each party points at the other.
Results
Detailed metrics are shared under NDA once the customer signs off, so this section covers what changed architecturally.
Application performance became predictable through dynamic path selection rather than contractual luck. Long-standing gaps at the edge were closed inside the same policy engine that steers traffic, so security did not become a second, parallel estate to run. Compliance reporting, which used to mean collecting evidence site by site, now comes out of centralized logs.
The internal network and security teams stopped firefighting per site and started working on the things the earlier firefighting had crowded out.