SD-WAN Reference Architecture — AstraWAN, Engineered by Ticvic
Ticvic-Logo

The architecture behind a production SD-WAN platform.

This is AstraWAN — a carrier-grade SD-WAN and SASE platform running production networks today. Ticvic engineered its core: the overlay design, the control plane, the security stack, and the packet path. What follows is the real architecture, not a marketing diagram.

Engineered by Ticvic Technologies for AstraWAN Networks. Published with permission.

Management, control, and data planes. GENEVE + IPSec secures control and management tunnels; GENEVE + ESP secures direct branch-to-branch data tunnels.

What the platform does

AstraWAN lets enterprises and service providers replace rigid MPLS circuits with secure, orchestrated connectivity over any transport — broadband internet, LTE/5G, or MPLS. It is fully software-based: it runs on off-the-shelf hardware, in a VM, or in the cloud, with security and application-aware services built into the same edge device.

Platform capabilities

Segregated control and data planes, scaled independently
Centralized, business-driven policy control
Multi-tenancy with a full MSP delivery model
Transport-agnostic: internet, MPLS, LTE/5G — any combination, per site
Policy-based automatic traffic rerouting
AIOps-enabled analytics with self-healing
Zero-touch deployment and centralized management
Application-aware QoS and assured performance
Integrated next-gen firewall and WAN optimization
SD-WAN extended to mobile devices, not just fixed branches

Core components

iManagerManagement

Centralized GUI orchestration, multi-tenant provisioning, active-standby HA

iReachControl

Device authentication, route reflection, IKE-less key management, global load balancer for remote users

iBranchData

Edge CPE — SD-WAN tunneling, BGP/OSPF routing, integrated NGFW / DPI / AAR security stack

AIOps AnalyticsObservability

ML-driven monitoring, self-healing, log analytics, forensics; active-active HA

iRoute (optional)Bootstrap

Zero-touch discovery — points a new iBranch to its assigned controller

iManager — management plane. One GUI to monitor, configure, and orchestrate every device across underlay and overlay. Multi-tenant; deploys on-premise, private cloud, or public cloud.

iReach — control plane. Authenticates every edge device and acts as route reflector and key management server, distributing routes, keys, and policy over iSOP — AstraWAN's BGP-based overlay protocol. Because keys are centrally orchestrated, the data plane needs no IKE negotiation — that's what makes the architecture scale.

iBranch — the edge. A software CPE at each site or in the cloud, forwarding traffic across one or more WAN transports with security inline in the data path: NGFW, DPI-based application classification, SSL/TLS inspection, application-aware routing, and NAT — SD-WAN, firewall, and traffic engineering converged in a single device.

AIOps Analytics. Ingests link, path, and flow telemetry from every edge device; delivers real-time visibility, automated incident response, capacity planning, and security forensics — with ML-driven self-healing.

How traffic flows

Three layers, each with its own trust boundary:

Underlay the raw internet / MPLS / LTE connections. A branch can use several simultaneously.
Overlay GENEVE encapsulation provides per-branch multi-tenant separation across control, management, and data planes.
Encryption IPSec secures all control- and management-plane tunnels from the very first packet. Branch-to-branch data traffic is encrypted with ESP, directly, without transiting a hub.

New sites onboard through zero-touch provisioning: the device is shipped to site, powered on, discovered, authenticated by certificate, and configured centrally — no engineer visit, no manual configuration.

Deployment topologies

Full mesh every branch talks directly to every other branch. Default; best for voice and low-latency traffic with policy enforced at the branch.
Hub & spoke (spoke-to-hub) spokes reach only the hub; used for e.g. ATM networks talking to a data center.
Hub & spoke (spoke-to-spoke via hub) inter-branch traffic transits the hub; used when inspection is centralized.
Partial mesh / spoke groups branches in a group connect directly; cross-group traffic transits full-meshed hubs.

Multi-tenancy runs through three portal tiers — Operator, MSP, and Customer — so the platform serves direct enterprise deployments and MSP-managed models from the same stack.

What makes this architecture different

SD-WAN extended natively to mobile devices handhelds join the overlay with the same feature set as a branch, including NGFW protection.
IKE-less, centrally orchestrated key distribution data-plane security that scales without per-tunnel negotiation.
AIOps with automated self-healing the network detects and repairs, not just alerts.
Converged NG-WAN edge SD-WAN + NGFW + application-aware routing on one device.
Transport- and hardware-agnostic COTS, VM, bare metal, or cloud.

Get the full reference architecture (PDF)

The complete 2-page document — component detail, traffic-flow design, topology guidance, and the security model.

No drip campaign. One email with the document.

Planning a platform like this?

Ticvic engineered this architecture end to end — control plane, overlay design, security stack, and packet path. If you're building or modernizing an SD-WAN, SASE, or network platform, start with the people who've shipped one.

Lets-Talk-Banner

Let's talk.

By submitting, you agree to our Privacy Policy. We only use your details to respond to this inquiry.

Need a Consultation!

Need help in turning your idea into a successful product? Talk to us. We can help you build your product quickly and ensure it can scale infinitely.

INDUSTRIES
SERVICES
LEGAL
OUR OFFICES
ind
India
Ticvic Technologies Pvt Ltd,
06, Vinir Tower, Outer Ring Road,
BTM 1st Stage,
Bengaluru,
Karnataka - 560068
India.
Mobile: 99808 00502 /97425 45210
info@ticvic.com
ind
India
Ticvic Technologies Pvt Ltd,
05, 1st Floor, Perumal Kovil Street,
Urapakkam,
Chengalpet Dist.
Tamil Nadu - 603210
India
Mobile: 99808 00502 /97425 45210
Tel: 044 43039730
info@ticvic.com
ind
USA
Ticvic Technologies LLC,
3001, Silver Fountain DR,
Leander,
Texas - 78641,
USA.
Mobile: +1 (347) 474 0430
Tel: +1 (214) 550 0252
info@ticvic.com
brand-logo
© 2026 .Ticvic Technology Private Limited. All Right Reserved