The architecture behind a production SD-WAN platform.
This is AstraWAN — a carrier-grade SD-WAN and SASE platform running production networks today. Ticvic engineered its core: the overlay design, the control plane, the security stack, and the packet path. What follows is the real architecture, not a marketing diagram.
Engineered by Ticvic Technologies for AstraWAN Networks. Published with permission.
A SD-WAN reference architecture is a documented, production-proven design showing how the management, control, and data planes of an SD-WAN fit together — which component owns which plane, how they authenticate and exchange keys, and how traffic is encrypted end to end. This one is AstraWAN, engineered and running in production today.
- GENEVE
- A tunnel encapsulation protocol that wraps traffic between SD-WAN endpoints, giving each branch and tenant its own isolated overlay.
- iSOP
- AstraWAN's own BGP-based overlay protocol, used by iReach to distribute routes, keys, and policy across every edge device.
- IKE-less key distribution
- Encryption keys are centrally generated and pushed to devices instead of negotiated per-tunnel, so new sites join without an IKE handshake.
- ESP
- Encapsulating Security Payload — the IPSec mechanism that encrypts and authenticates branch-to-branch data traffic directly, without transiting a hub.
What the platform does
AstraWAN lets enterprises and service providers replace rigid MPLS circuits with secure, orchestrated connectivity over any transport — broadband internet, LTE/5G, or MPLS. It is fully software-based: it runs on off-the-shelf hardware, in a VM, or in the cloud, with security and application-aware services built into the same edge device.
Core components
Four core components plus one optional bootstrap — each owning exactly one plane.
iManager
Centralized GUI orchestration, multi-tenant provisioning, active-standby HA
iReach
Device authentication, route reflection, IKE-less key management, global load balancer for remote users
iBranch
Edge CPE — SD-WAN tunneling, BGP/OSPF routing, integrated NGFW / DPI / AAR security stack
AIOps Analytics
ML-driven monitoring, self-healing, log analytics, forensics; active-active HA
iRoute (optional)
Zero-touch discovery — points a new iBranch to its assigned controller
iManager — management plane. One GUI to monitor, configure, and orchestrate every device across underlay and overlay. Multi-tenant; deploys on-premise, private cloud, or public cloud.
iReach — control plane. Authenticates every edge device and acts as route reflector and key management server, distributing routes, keys, and policy over iSOP — AstraWAN's BGP-based overlay protocol. Because keys are centrally orchestrated, the data plane needs no IKE negotiation — that's what makes the architecture scale.
iBranch — the edge. A software CPE at each site or in the cloud, forwarding traffic across one or more WAN transports with security inline in the data path: NGFW, DPI-based application classification, SSL/TLS inspection, application-aware routing, and NAT — SD-WAN, firewall, and traffic engineering converged in a single device.
AIOps Analytics. Ingests link, path, and flow telemetry from every edge device; delivers real-time visibility, automated incident response, capacity planning, and security forensics — with ML-driven self-healing.
How traffic flows
Three layers, each with its own trust boundary:
Underlay
the raw internet / MPLS / LTE connections. A branch can use several simultaneously.
Overlay
GENEVE encapsulation provides per-branch multi-tenant separation across control, management, and data planes.
Encryption
IPSec secures all control- and management-plane tunnels from the very first packet. Branch-to-branch data traffic is encrypted with ESP, directly, without transiting a hub.
Deployment topologies
Full mesh
every branch talks directly to every other branch. Default; best for voice and low-latency traffic with policy enforced at the branch.
Hub & spoke (spoke-to-hub)
spokes reach only the hub; used for e.g. ATM networks talking to a data center.
Hub & spoke (spoke-to-spoke via hub)
inter-branch traffic transits the hub; used when inspection is centralized.
Partial mesh / spoke groups
branches in a group connect directly; cross-group traffic transits full-meshed hubs.
Multi-tenancy runs through three portal tiers — Operator, MSP, and Customer — so the platform serves direct enterprise deployments and MSP-managed models from the same stack.
What makes this architecture different
SD-WAN extended natively to mobile devices — handhelds join the overlay with the same feature set as a branch, including NGFW protection.
IKE-less, centrally orchestrated key distribution — data-plane security that scales without per-tunnel negotiation.
AIOps with automated self-healing — the network detects and repairs, not just alerts.
Converged NG-WAN edge — SD-WAN + NGFW + application-aware routing on one device.
Transport- and hardware-agnostic — COTS, VM, bare metal, or cloud.
Get the full reference architecture (PDF)
The complete 2-page document — component detail, traffic-flow design, topology guidance, and the security model.
Planning a platform like this?
Ticvic engineered this architecture end to end — control plane, overlay design, security stack, and packet path. If you're building or modernizing an SD-WAN, SASE, or network platform, start with the people who've shipped one.