The architecture behind a production SD-WAN platform.
This is AstraWAN — a carrier-grade SD-WAN and SASE platform running production networks today. Ticvic engineered its core: the overlay design, the control plane, the security stack, and the packet path. What follows is the real architecture, not a marketing diagram.
Engineered by Ticvic Technologies for AstraWAN Networks. Published with permission.
What the platform does
AstraWAN lets enterprises and service providers replace rigid MPLS circuits with secure, orchestrated connectivity over any transport — broadband internet, LTE/5G, or MPLS. It is fully software-based: it runs on off-the-shelf hardware, in a VM, or in the cloud, with security and application-aware services built into the same edge device.
Platform capabilities
Core components
| Component | Plane | Role |
|---|---|---|
| iManager | Management | Centralized GUI orchestration, multi-tenant provisioning, active-standby HA |
| iReach | Control | Device authentication, route reflection, IKE-less key management, global load balancer for remote users |
| iBranch | Data | Edge CPE — SD-WAN tunneling, BGP/OSPF routing, integrated NGFW / DPI / AAR security stack |
| AIOps Analytics | Observability | ML-driven monitoring, self-healing, log analytics, forensics; active-active HA |
| iRoute (optional) | Bootstrap | Zero-touch discovery — points a new iBranch to its assigned controller |
Centralized GUI orchestration, multi-tenant provisioning, active-standby HA
Device authentication, route reflection, IKE-less key management, global load balancer for remote users
Edge CPE — SD-WAN tunneling, BGP/OSPF routing, integrated NGFW / DPI / AAR security stack
ML-driven monitoring, self-healing, log analytics, forensics; active-active HA
Zero-touch discovery — points a new iBranch to its assigned controller
iManager — management plane. One GUI to monitor, configure, and orchestrate every device across underlay and overlay. Multi-tenant; deploys on-premise, private cloud, or public cloud.
iReach — control plane. Authenticates every edge device and acts as route reflector and key management server, distributing routes, keys, and policy over iSOP — AstraWAN's BGP-based overlay protocol. Because keys are centrally orchestrated, the data plane needs no IKE negotiation — that's what makes the architecture scale.
iBranch — the edge. A software CPE at each site or in the cloud, forwarding traffic across one or more WAN transports with security inline in the data path: NGFW, DPI-based application classification, SSL/TLS inspection, application-aware routing, and NAT — SD-WAN, firewall, and traffic engineering converged in a single device.
AIOps Analytics. Ingests link, path, and flow telemetry from every edge device; delivers real-time visibility, automated incident response, capacity planning, and security forensics — with ML-driven self-healing.
How traffic flows
Three layers, each with its own trust boundary:
New sites onboard through zero-touch provisioning: the device is shipped to site, powered on, discovered, authenticated by certificate, and configured centrally — no engineer visit, no manual configuration.
Deployment topologies
Multi-tenancy runs through three portal tiers — Operator, MSP, and Customer — so the platform serves direct enterprise deployments and MSP-managed models from the same stack.
What makes this architecture different
Get the full reference architecture (PDF)
The complete 2-page document — component detail, traffic-flow design, topology guidance, and the security model.
No drip campaign. One email with the document.
Planning a platform like this?
Ticvic engineered this architecture end to end — control plane, overlay design, security stack, and packet path. If you're building or modernizing an SD-WAN, SASE, or network platform, start with the people who've shipped one.

Let's talk.
Need a Consultation!
Need help in turning your idea into a successful product? Talk to us. We can help you build your product quickly and ensure it can scale infinitely.
Let's talk.
