The WAN was designed for a factory that no longer exists
Most manufacturing WANs were architected for a simpler brief: connect the plant to head office, carry ERP traffic and email, and keep the link up. For years an MPLS circuit did that job well. The traffic was predictable, the applications lived in a corporate data centre, and the production floor was largely an island of its own.
That factory no longer exists. Production lines now depend on cloud-hosted MES and quality systems. Machines report telemetry to vendor platforms for predictive maintenance. Video, IP cameras, and increasingly bandwidth-hungry sensor data share the same links as the ERP. And the moment any of it stops, the line stops with it. A network that was designed to be adequate is now a constraint on output.
Software-defined WAN addresses this, but the reasons it matters in manufacturing are specific to the environment. It is worth being precise about them rather than reaching for generic benefits.
Why manufacturing is a harder case
Three characteristics make production sites different from a typical branch network, and each one exposes a weakness in the legacy WAN.
Downtime has a direct, measurable cost
In an office, a WAN outage is disruptive. On a production line, it can halt output, spoil in-progress batches, and idle expensive plant. The tolerance for unplanned downtime is far lower, and the case for genuine redundancy (not a failover link that is never tested) is far stronger.
The traffic is mixed and latency-sensitive
A manufacturing site carries an unusually varied traffic profile on a single set of links: real-time control and monitoring, cloud applications, large file transfers, voice, and video. Some of it tolerates delay and some of it does not. A network that treats all of it identically will let a backup job starve a control system of bandwidth at exactly the wrong moment.
OT and IT share infrastructure they were never meant to share
Operational technology (the PLCs, HMIs, and control systems that run the plant) increasingly rides the same physical network as corporate IT. That convergence is efficient, but it collapses a boundary that used to provide security by isolation. A flat network means a compromised office laptop and a production controller sit in the same broadcast domain, which is a risk no manufacturer should accept.
Legacy WAN is transport-bound and application-blind
Traditional MPLS gives you one expensive path and no visibility into what is actually flowing across it. You cannot prioritise the traffic that matters because the network does not understand the difference between a control-system heartbeat and a Windows update. SD-WAN inverts both of those limitations.
How SD-WAN addresses it
SD-WAN separates the control of the network from the physical transport underneath it. Instead of one circuit doing one job, an edge appliance at each site can use several transports at once (MPLS, business broadband, fibre, and cellular) and make intelligent, per-application decisions about which path each flow should take.
Application-aware routing
The edge device identifies applications and applies policy to each one. Cloud MES traffic can be routed directly to the internet rather than backhauled through a distant data centre. Latency-sensitive control traffic can be pinned to the most stable path and given priority. Bulk transfers can be pushed onto cheaper broadband. The network finally understands what it is carrying and acts accordingly.
Transport independence and real failover
Because the appliance uses multiple links simultaneously, the loss of any one of them is a non-event. Sub-second failover moves active sessions to a healthy path without dropping the connection. Adding a 4G or 5G link as a tertiary transport gives a site resilience even against a physical cable cut, which for a single-circuit MPLS site would mean a full outage.
Centralised orchestration and visibility
Policy is defined once, centrally, and pushed to every site. For an organisation running several plants this is the difference between managing each site by hand and managing the estate as one system. It also delivers the visibility that the legacy WAN never could: which applications are consuming bandwidth, where latency is building, and how each transport is performing, across every site.
| Requirement | Legacy MPLS | SD-WAN |
|---|---|---|
| Resilience | Single path; failover often untested | Multiple active transports; sub-second failover |
| Application priority | Blind to application type | Per-application policy and QoS |
| Cloud traffic | Backhauled through the data centre | Routed direct, with local breakout |
| Adding a site | New circuit, long lead time | Ship an appliance; provision centrally |
| Visibility | Little to none | Per-application, per-link, per-site |
| Segmentation | Difficult on a flat WAN | Native, policy-driven |
Security and IT/OT segmentation
This is the point where a networking project becomes a security project, and where the two should never be treated as separate exercises. SD-WAN is not only a connectivity upgrade. It is an opportunity to re-establish the segmentation that IT/OT convergence eroded.
A well-designed deployment carries production, corporate, guest, and management traffic in separate segments, with policy governing exactly what may cross between them. The control network can be isolated so that it is reachable only by the specific systems that need it, and nothing else. This limits the blast radius of an incident: a compromise on the corporate side cannot traverse laterally into the plant if the boundary is enforced in the fabric rather than assumed.
Extending this toward a secure multi-site or SASE model folds inspection, secure web access, and consistent policy enforcement into the same architecture, so that every site is protected to the same standard rather than each one being a separate problem. Segmentation and connectivity are two halves of the same design, and treating network access control as part of the WAN project rather than a later add-on is what makes the result defensible.
"On a production site, the network and its security are the same conversation. The moment OT and IT share a link, connectivity decisions become security decisions. Designing them together is the only way the result holds up."
Edge7 Networks, Networking PracticeMigrating without stopping the line
The objection that stalls most WAN projects in manufacturing is risk. You cannot take a production site offline for a cutover, and nobody wants to be the reason a line stopped. A well-planned SD-WAN migration is designed around exactly this constraint.
The usual approach runs SD-WAN in parallel with the existing MPLS rather than replacing it in one step. The edge appliance is installed alongside the current router, adopts the existing circuit as one of its transports, and a second link is added beside it. Traffic is migrated policy by policy, with the option to fall back instantly if anything behaves unexpectedly. Only once the new fabric has proven itself is the legacy circuit reduced or retired. The line never depends on the cutover succeeding on the first attempt.
Survey the OT environment before you design
The single most common cause of trouble in manufacturing network projects is an incomplete picture of what is actually connected on the plant floor. Legacy controllers, undocumented devices, and vendor remote-access arrangements all need to be found and understood before segmentation policy is written. A site survey is not optional groundwork. It is the design.
Where to start
A sensible first step is not a procurement exercise. It is an assessment of the current state: what each site's connectivity looks like, how resilient it actually is, what is running on the OT network, and where the segmentation gaps are. That picture is what turns a generic SD-WAN pitch into a design that fits your plants.
Edge7 Networks has worked on SD-WAN and multi-site connectivity since 2018, and combines it with the security and segmentation work that manufacturing environments require. If you are running production sites on connectivity that has become a constraint, a site survey is the right place to begin.