What is our primary use case?
We use Cisco SD-WAN backup as a failover, from the MPLS circuit. We also use the solution at remote sites where we were going over cellular satellites to secure the data.
How has it helped my organization?
We deployed the Cisco SD-WAN FlexVPN version. At the organization I was at, the Cisco SD-WAN solution allowed us to reduce costs by getting off MPLS circuits and using a regular IP provider, cellular provider, or satellite provider for primary and backup networks. The SD-WAN solution cut costs and was well adopted by the IT department since most corporate IT departments are Cisco brand.
What is most valuable?
Cisco products are rated to handle the heat and are very rugged, making them a good corporate standard. They are slightly more expensive than some other products but are still an affordable corporate-grade solution. We have had some issues with the ISO versions of the SD-WAN, but the FlexVPN solution has since resolved them. Cisco SD-WAN is a good, solid product, but requires a certain skill set to use. We cannot simply switch from Peplink to Cisco as the two are different. The upgrade to iOS 11 has fixed any issues we had with the product, and it has been reliable for the past four years.
What needs improvement?
Cisco's management function has room for improvement, and I believe they have something for that now. At the time, the management of the device and the configuration of the device could have been more user-friendly, with a point-and-click or GUI style, instead of using the command line. We had to use the command line to configure everything. I believe Cisco has a management port.
The initial setup is complex and can be improved.
I would like to have stable, SBI, or IPS functions in the routers at our edge points.
For how long have I used the solution?
I have been using the solution for 15 years.
What do I think about the stability of the solution?
My first impression of the solution's stability was that it was quirky. We had some dropped sessions where the VPN session would just drop if we had a carrier drop and some sessions where the solution would drop the VPN session. It wasn't a virtual device; it was a piece of hardware in the data center. I saw it and had that drawing. The solution would drop the VPN sessions whenever they got too loaded because we had a priority on the session screen devices and they had an issue there. My initial thought was, "Why didn't we use something else?" After Cisco made changes to their FlexVPN appliance in iOS, it became really stable. We had a workaround for it, which was to tear down the session every few hours and round-robin the remote devices to set up the sessions. This would help to load balance the solution into the data center. After Cisco fixed their software, we no longer had to do that and we didn't have any issues because it would automatically shift the remote to set the load across all the appliances.
What do I think about the scalability of the solution?
I give the scalability of the solution a nine out of ten. The solution scales out very well. We just need the right product in our data center to integrate Cisco SD-WAN. For this particular solution, Cisco SD-WAN would scale out successfully. The amount of memory required is substantial, as we have many TCP connections that require a lot of memory. We also need a lot of processing files. Initially, the solution was lacking in this area, but it has since been improved. We used the solution for twelve hundred sites, while the company I was at previously had twelve thousand. They have since migrated to Palo Alto, although I have not used it. We were unable to use it on remote sites as Palo Alto did not have a hardware version. However, Palo Alto now has a hardware version, so we can use it in a controlled environment.
How are customer service and support?
The technical support is good.
Which solution did I use previously and why did I switch?
I had previously used a solution called SpamFeed Network, which is owned by ComTech EF Data, for application acceleration over satellite. It was Linux based on OpenSuite and had compression, security, and firewall features, as well as packet inspection if desired. It worked very well, but was extremely expensive, more than double the price of a Cisco solution.
How was the initial setup?
The initial setup was complex. If we weren't familiar with it, we needed to be aware of the solution's features and set up our VPN connection. It was more cumbersome, but it worked out. Cisco has the best documentation that I have seen so far; we just have to read and find it. Cisco does a good job of making it available, but we have to be familiar with their product to understand it.
I've never had eight or nine people on a phone call before; normally, it would only be two. With the new security model, we need a minimum of two people: one in the data center to manage the firewall and one in the field to do the configuration and installation. We had nine people on the call because we had project coordinators, but this is not Cisco's best practice. This is how the younger IT people operate. I prefer to follow the Purdue model, which only requires two people.
What about the implementation team?
The implementation was completed in-house.
What was our ROI?
There has been a return on investment since we began deploying Cisco SD-WAN in 2018, prior to the onset of COVID. They are still functioning, and they will begin refreshing their devices and changing them out at five years. They usually start changing the model when they are able to write off the product, and they typically acclimate over a three-year period or when Cisco discontinues the product. They are still hanging in there.
What's my experience with pricing, setup cost, and licensing?
I give the price a seven out of ten. Cisco hasn't quite reached the top yet, from what I've seen. I didn't look at the price, but I'm sure VMware is more expensive than Cisco Verdi.
Which other solutions did I evaluate?
I evaluated Mushroom Networks, but they did not meet corporate standards. The company may have considered Cradlepoint, Peplink, or Mushroom networks, but they ultimately decided to go with Cisco or Juniper, which are more widely used.
What other advice do I have?
I give the solution a five out of ten because there are some competitors that provide a better interface, which is easier to configure and requires less scripting. Cisco is slower to implement such features. Cisco has some better products with a management system and virtual VPN solution, as they have been doing this for a longer time.
Cisco SD-WAN is not quite as easy to configure, as Peplink or mushroom network. From what I can see on the Cradlepoint, we have to have a little more skill for Cisco. Cisco SD-WAN does work well and It fails over well. What I'd do is read due to the session to load balance at the time, but I think Cisco has since automated that. Cisco is a corporate standard and if it was my money, I'd probably not use Cisco due to cost. Cisco does actually have products that are more cost-effective than industrial products on the market, such as the Eagle30 product. Cisco is more on the high-end cost-wise. Cisco SD-WAN is not as easy to manipulate a program. If we're looking for people that are trained to administer Cisco, it is a lot easier to find compared to any other solutions even though the other products may be easier to install. A lot of people won't use them because they are not the industry standard.
We have to give Cisco credit. They have put a lot of effort into education, which I appreciate. They have excellent documentation on how to do basic configurations, which is enough to get our network up and running. That's what I like about Cisco.
Cisco SD-WAN is a good corporate solution that scales well. Cisco is prompt in providing fixes. They may not be instantaneous, but if we open a case, they are usually quick to provide a solution. We should opt for a product that has been around for a while; if it is a new product, we may encounter a few issues. We should stick with something that has been around for at least a year or two, such as Cisco. I can confidently say that Cisco is stable and is a corporate standard.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.