SD-WAN Reference Architecture — AstraWAN, Engineered by Ticvic
Reference Architecture · SD-WAN

The architecture behind a production SD-WAN platform.

This is AstraWAN — a carrier-grade SD-WAN and SASE platform running production networks today. Ticvic engineered its core: the overlay design, the control plane, the security stack, and the packet path. What follows is the real architecture, not a marketing diagram.

Engineered by Ticvic Technologies for AstraWAN Networks. Published with permission.

What is a SD-WAN reference architecture?

A SD-WAN reference architecture is a documented, production-proven design showing how the management, control, and data planes of an SD-WAN fit together — which component owns which plane, how they authenticate and exchange keys, and how traffic is encrypted end to end. This one is AstraWAN, engineered and running in production today.

AstraWAN SD-WAN — Reference Architecture Management, Control & Data Plane Overview MANAGEMENT PLANE CONTROL PLANE DATA PLANE UNDERLAY iManager Management Plane • GUI orchestration iReach Control Plane • route reflector, KMS AIOps Analytics ML monitoring • self-healing iRoute (optional) ZTP bootstrap only iBranch — Site A Edge CPE • NGFW / DPI / AAR / NAT iBranch — Site B Edge CPE • NGFW / DPI / AAR / NAT LAN LAN Underlay Transport Internet / MPLS / LTE-5G (any combination, per site) Core Overlay: GENEVE + IPSec Mgmt Overlay: GENEVE + IPSec GENEVE + IPSec ZTP bootstrap (IPSec) for any new iBranch Control Overlay: GENEVE + IPSec Control Overlay: GENEVE + IPSec Data Overlay: GENEVE + ESP (direct branch-to-branch) Control / Management (GENEVE + IPSec) Data Plane (GENEVE + ESP) ZTP Bootstrap (IPSec)
Management, control, and data planes. GENEVE + IPSec secures control and management tunnels; GENEVE + ESP secures direct branch-to-branch data tunnels.
GENEVE
A tunnel encapsulation protocol that wraps traffic between SD-WAN endpoints, giving each branch and tenant its own isolated overlay.
iSOP
AstraWAN's own BGP-based overlay protocol, used by iReach to distribute routes, keys, and policy across every edge device.
IKE-less key distribution
Encryption keys are centrally generated and pushed to devices instead of negotiated per-tunnel, so new sites join without an IKE handshake.
ESP
Encapsulating Security Payload — the IPSec mechanism that encrypts and authenticates branch-to-branch data traffic directly, without transiting a hub.
Section 01

What the platform does

AstraWAN lets enterprises and service providers replace rigid MPLS circuits with secure, orchestrated connectivity over any transport — broadband internet, LTE/5G, or MPLS. It is fully software-based: it runs on off-the-shelf hardware, in a VM, or in the cloud, with security and application-aware services built into the same edge device.

Segregated control and data planes, scaled independently
Centralized, business-driven policy control
Multi-tenancy with a full MSP delivery model
Transport-agnostic: internet, MPLS, LTE/5G — any combination, per site
Policy-based automatic traffic rerouting
AIOps-enabled analytics with self-healing
Zero-touch deployment and centralized management
Application-aware QoS and assured performance
Integrated next-gen firewall and WAN optimization
SD-WAN extended to mobile devices, not just fixed branches
Section 02

Core components

Four core components plus one optional bootstrap — each owning exactly one plane.

Management

iManager

Centralized GUI orchestration, multi-tenant provisioning, active-standby HA

Control

iReach

Device authentication, route reflection, IKE-less key management, global load balancer for remote users

Data

iBranch

Edge CPE — SD-WAN tunneling, BGP/OSPF routing, integrated NGFW / DPI / AAR security stack

Observability

AIOps Analytics

ML-driven monitoring, self-healing, log analytics, forensics; active-active HA

Bootstrap

iRoute (optional)

Zero-touch discovery — points a new iBranch to its assigned controller

iManager — management plane. One GUI to monitor, configure, and orchestrate every device across underlay and overlay. Multi-tenant; deploys on-premise, private cloud, or public cloud.

iReach — control plane. Authenticates every edge device and acts as route reflector and key management server, distributing routes, keys, and policy over iSOP — AstraWAN's BGP-based overlay protocol. Because keys are centrally orchestrated, the data plane needs no IKE negotiation — that's what makes the architecture scale.

iBranch — the edge. A software CPE at each site or in the cloud, forwarding traffic across one or more WAN transports with security inline in the data path: NGFW, DPI-based application classification, SSL/TLS inspection, application-aware routing, and NAT — SD-WAN, firewall, and traffic engineering converged in a single device.

AIOps Analytics. Ingests link, path, and flow telemetry from every edge device; delivers real-time visibility, automated incident response, capacity planning, and security forensics — with ML-driven self-healing.

Section 03

How traffic flows

Three layers, each with its own trust boundary:

01

Underlay

the raw internet / MPLS / LTE connections. A branch can use several simultaneously.

02

Overlay

GENEVE encapsulation provides per-branch multi-tenant separation across control, management, and data planes.

03

Encryption

IPSec secures all control- and management-plane tunnels from the very first packet. Branch-to-branch data traffic is encrypted with ESP, directly, without transiting a hub.

Zero-touch onboarding: the device is shipped to site, powered on, discovered, authenticated by certificate, and configured centrally — no engineer visit, no manual configuration.
Section 04

Deployment topologies

Full mesh

every branch talks directly to every other branch. Default; best for voice and low-latency traffic with policy enforced at the branch.

Hub & spoke (spoke-to-hub)

spokes reach only the hub; used for e.g. ATM networks talking to a data center.

Hub & spoke (spoke-to-spoke via hub)

inter-branch traffic transits the hub; used when inspection is centralized.

Partial mesh / spoke groups

branches in a group connect directly; cross-group traffic transits full-meshed hubs.

Multi-tenancy runs through three portal tiers — Operator, MSP, and Customer — so the platform serves direct enterprise deployments and MSP-managed models from the same stack.

Section 05

What makes this architecture different

SD-WAN extended natively to mobile deviceshandhelds join the overlay with the same feature set as a branch, including NGFW protection.

IKE-less, centrally orchestrated key distributiondata-plane security that scales without per-tunnel negotiation.

AIOps with automated self-healingthe network detects and repairs, not just alerts.

Converged NG-WAN edgeSD-WAN + NGFW + application-aware routing on one device.

Transport- and hardware-agnosticCOTS, VM, bare metal, or cloud.

Full document

Get the full reference architecture (PDF)

The complete 2-page document — component detail, traffic-flow design, topology guidance, and the security model.

No drip campaign. One email with the document.

Planning a platform like this?

Planning a platform like this?

Ticvic engineered this architecture end to end — control plane, overlay design, security stack, and packet path. If you're building or modernizing an SD-WAN, SASE, or network platform, start with the people who've shipped one.