Networking

SD-WAN Connectivity for Irish Manufacturing Sites

Production environments push legacy MPLS networks to their limits. SD-WAN delivers the redundancy, application visibility, and IT/OT segmentation that manufacturing sites need. Here is what that looks like in practice.

E7
Edge7 Networks Team
Networking & Security Specialists
14 February 2025
7 min read
Share

The WAN was designed for a factory that no longer exists

Most manufacturing WANs were architected for a simpler brief: connect the plant to head office, carry ERP traffic and email, and keep the link up. For years an MPLS circuit did that job well. The traffic was predictable, the applications lived in a corporate data centre, and the production floor was largely an island of its own.

That factory no longer exists. Production lines now depend on cloud-hosted MES and quality systems. Machines report telemetry to vendor platforms for predictive maintenance. Video, IP cameras, and increasingly bandwidth-hungry sensor data share the same links as the ERP. And the moment any of it stops, the line stops with it. A network that was designed to be adequate is now a constraint on output.

Software-defined WAN addresses this, but the reasons it matters in manufacturing are specific to the environment. It is worth being precise about them rather than reaching for generic benefits.

Why manufacturing is a harder case

Three characteristics make production sites different from a typical branch network, and each one exposes a weakness in the legacy WAN.

Downtime has a direct, measurable cost

In an office, a WAN outage is disruptive. On a production line, it can halt output, spoil in-progress batches, and idle expensive plant. The tolerance for unplanned downtime is far lower, and the case for genuine redundancy (not a failover link that is never tested) is far stronger.

The traffic is mixed and latency-sensitive

A manufacturing site carries an unusually varied traffic profile on a single set of links: real-time control and monitoring, cloud applications, large file transfers, voice, and video. Some of it tolerates delay and some of it does not. A network that treats all of it identically will let a backup job starve a control system of bandwidth at exactly the wrong moment.

OT and IT share infrastructure they were never meant to share

Operational technology (the PLCs, HMIs, and control systems that run the plant) increasingly rides the same physical network as corporate IT. That convergence is efficient, but it collapses a boundary that used to provide security by isolation. A flat network means a compromised office laptop and a production controller sit in the same broadcast domain, which is a risk no manufacturer should accept.

The core issue

Legacy WAN is transport-bound and application-blind

Traditional MPLS gives you one expensive path and no visibility into what is actually flowing across it. You cannot prioritise the traffic that matters because the network does not understand the difference between a control-system heartbeat and a Windows update. SD-WAN inverts both of those limitations.

How SD-WAN addresses it

SD-WAN separates the control of the network from the physical transport underneath it. Instead of one circuit doing one job, an edge appliance at each site can use several transports at once (MPLS, business broadband, fibre, and cellular) and make intelligent, per-application decisions about which path each flow should take.

Application-aware routing

The edge device identifies applications and applies policy to each one. Cloud MES traffic can be routed directly to the internet rather than backhauled through a distant data centre. Latency-sensitive control traffic can be pinned to the most stable path and given priority. Bulk transfers can be pushed onto cheaper broadband. The network finally understands what it is carrying and acts accordingly.

Transport independence and real failover

Because the appliance uses multiple links simultaneously, the loss of any one of them is a non-event. Sub-second failover moves active sessions to a healthy path without dropping the connection. Adding a 4G or 5G link as a tertiary transport gives a site resilience even against a physical cable cut, which for a single-circuit MPLS site would mean a full outage.

Centralised orchestration and visibility

Policy is defined once, centrally, and pushed to every site. For an organisation running several plants this is the difference between managing each site by hand and managing the estate as one system. It also delivers the visibility that the legacy WAN never could: which applications are consuming bandwidth, where latency is building, and how each transport is performing, across every site.

RequirementLegacy MPLSSD-WAN
ResilienceSingle path; failover often untestedMultiple active transports; sub-second failover
Application priorityBlind to application typePer-application policy and QoS
Cloud trafficBackhauled through the data centreRouted direct, with local breakout
Adding a siteNew circuit, long lead timeShip an appliance; provision centrally
VisibilityLittle to nonePer-application, per-link, per-site
SegmentationDifficult on a flat WANNative, policy-driven

Security and IT/OT segmentation

This is the point where a networking project becomes a security project, and where the two should never be treated as separate exercises. SD-WAN is not only a connectivity upgrade. It is an opportunity to re-establish the segmentation that IT/OT convergence eroded.

A well-designed deployment carries production, corporate, guest, and management traffic in separate segments, with policy governing exactly what may cross between them. The control network can be isolated so that it is reachable only by the specific systems that need it, and nothing else. This limits the blast radius of an incident: a compromise on the corporate side cannot traverse laterally into the plant if the boundary is enforced in the fabric rather than assumed.

Extending this toward a secure multi-site or SASE model folds inspection, secure web access, and consistent policy enforcement into the same architecture, so that every site is protected to the same standard rather than each one being a separate problem. Segmentation and connectivity are two halves of the same design, and treating network access control as part of the WAN project rather than a later add-on is what makes the result defensible.

"On a production site, the network and its security are the same conversation. The moment OT and IT share a link, connectivity decisions become security decisions. Designing them together is the only way the result holds up."

Edge7 Networks, Networking Practice

Migrating without stopping the line

The objection that stalls most WAN projects in manufacturing is risk. You cannot take a production site offline for a cutover, and nobody wants to be the reason a line stopped. A well-planned SD-WAN migration is designed around exactly this constraint.

The usual approach runs SD-WAN in parallel with the existing MPLS rather than replacing it in one step. The edge appliance is installed alongside the current router, adopts the existing circuit as one of its transports, and a second link is added beside it. Traffic is migrated policy by policy, with the option to fall back instantly if anything behaves unexpectedly. Only once the new fabric has proven itself is the legacy circuit reduced or retired. The line never depends on the cutover succeeding on the first attempt.

Practical note

Survey the OT environment before you design

The single most common cause of trouble in manufacturing network projects is an incomplete picture of what is actually connected on the plant floor. Legacy controllers, undocumented devices, and vendor remote-access arrangements all need to be found and understood before segmentation policy is written. A site survey is not optional groundwork. It is the design.

Where to start

A sensible first step is not a procurement exercise. It is an assessment of the current state: what each site's connectivity looks like, how resilient it actually is, what is running on the OT network, and where the segmentation gaps are. That picture is what turns a generic SD-WAN pitch into a design that fits your plants.

Edge7 Networks has worked on SD-WAN and multi-site connectivity since 2018, and combines it with the security and segmentation work that manufacturing environments require. If you are running production sites on connectivity that has become a constraint, a site survey is the right place to begin.


E7
Edge7 Networks Team
Networking & Security Specialists, Ireland & UK

Edge7 Networks is a specialist networking and security provider, founded in 2018 on SD-WAN. Our team works with IT leaders across Ireland and the UK on enterprise networking, managed security, and compliance. We hold ISO 27001:2022, ISO 9001:2015, and Cyber Essentials certifications.

Is your WAN keeping up with the plant?

Our engineers design and run multi-site networks for manufacturers across Ireland and the UK. If you would like to talk through your sites, we are easy to reach.