SD-WAN for UAE Businesses With More Than One Site

SD-WAN builds encrypted tunnels between your sites over whatever circuits each site already has, measures every path all the time, and moves each application onto the path that currently suits it, with the rules set once from a central console. For a UAE business it usually pays at three or more sites, or wherever a site runs two unlike circuits such as fibre plus 5G. With two sites on steady fibre, a tunnel between two firewalls is normally the better engineering answer.

Our guide to choosing a business router for a UAE office covers when SD-WAN is worth considering at all. This article is for the business that has already decided it has the sites to justify it, and wants to know what to specify, what to ask the vendor, and where these projects go wrong.

What changes compared with an ordinary site to site VPN

A traditional VPN between a Business Bay head office and a Jebel Ali warehouse is a tunnel that is either up or down. If the fibre degrades but does not fail, voice calls break up and nothing moves them. SD-WAN adds three things to that tunnel: continuous measurement of loss, latency and jitter on every path, policy that uses those measurements per application, and central configuration so a new site in JLT is set up from a template rather than typed in by hand.

Cisco's Catalyst SD-WAN Getting Started Guide (updated 7 July 2026) shows how that is split up. The SD-WAN Manager is the dashboard, the SD-WAN Controller decides how data traffic flows, the SD-WAN Validator introduces edge routers to the controllers, and the edge routers at each site carry the traffic. Cisco's guide covers hosting the controllers in Microsoft Azure or AWS. Other platforms fold these roles into one cloud dashboard, but the same jobs exist somewhere, and you should know who runs each one.

Is running encrypted tunnels between UAE sites allowed

Yes, for a business connecting its own network. In a statement dated 31 July 2016, the regulator now called TDRA said there are "no regulations which prevent the use of VPN technology" by companies, institutions and banks reaching their internal networks over the internet. The same statement makes clear that misuse, such as hiding an address to commit or conceal a crime, remains an offence.

Voice is a separate question. Carrying your own IP phone traffic between your own sites is one thing, and what calling services a business may use is another, covered in our article on choosing IP phones for a UAE office. Confirm the voice design with your provider before you build SD-WAN policy around it.

The figure that matters most: how quickly it reacts

Every SD-WAN brochure says "application aware routing". The useful question is how many seconds pass between a path going bad and traffic moving off it, with the settings you will actually run. The answer differs a great deal between platforms, and between defaults and tuned settings on the same platform.

Platform and sourceHow paths are measuredWhat the documentation says about reaction
Cisco Catalyst SD-WAN, default settings (Cisco support document, 2 February 2024)BFD hello every 1 second, results grouped into 10 minute poll intervalsSix poll intervals are averaged, so SLA decisions rest on one hour of data
Cisco enhanced application aware routing (IOS XE 17.12.1a and Manager 20.12.1 or later)BFD plus inline data measurementPoll interval can be reduced to a minimum of 10 seconds
Cisco Meraki MX AutoVPN (Meraki SD-WAN best practice guide, read September 2026)Probe of about 100 bytes every 1 second on every tunnelAbout 500 ms with active active tunnels and performance rules for loss under 5%, under 100 ms when a circuit fails outright

Put that beside the voice target. ITU-T Recommendation G.114 (May 2003) says that below 150 ms of one way delay most speech applications feel essentially interactive. A Catalyst deployment left on defaults can average away a bad half hour on one circuit, and your Dubai Silicon Oasis office will hear it before the dashboard does. Cisco's own document warns against cutting the poll interval without checking how many probes each measurement then rests on, because too few samples give false alarms. Tuning is a design task, so make it a line item in the project rather than an afterthought.

Choosing circuits for each site

SD-WAN is only as good as the paths underneath it. As of September 2026, e&'s managed SD-WAN page lists routing across MPLS, 4G/5G and broadband, a pay as you grow model, and 24x7 management with co-managed options. du also sells SD-WAN with managed migration. So the first decision for a UAE business is not which box to buy, but whether to buy the platform yourself or take it as a carrier service.

  • Buy and run it yourself when you have staff who will own the policy, you want circuits from both carriers at every site, or you have sites outside the UAE.
  • Take a managed service when nobody in house will look at the dashboard weekly. Read the SLA for what it measures: circuit availability and application performance are different promises.
  • Mix circuit types deliberately. Two fibre circuits in the same riser of a Business Bay tower fail together. Fibre from one carrier plus 5G from the other gives the software two paths that rarely fail for the same reason.

Where these projects go wrong in practice

Tunnels that will not form behind carrier NAT

A Cisco support document updated 21 April 2025 states that port or address restricted NAT and symmetric NAT do not work together, so tunnels between two sites behind those NAT types fail to come up. You rarely control the NAT type on a carrier supplied router you cannot bridge, or on a mobile data service. The fix is usually a static public address or static NAT for the tunnel traffic. Ask for this when you order each circuit, because changing it later means another carrier ticket per site.

Tunnel counts nobody worked out

Full mesh grows faster than people expect. The number of site pairs is n(n-1)/2, so six sites make 15 pairs. Give every site two circuits and let each circuit reach both circuits at the far end, and each pair carries four tunnels: 60 tunnels, every one probed continuously. Most businesses of this size do better with hub and spoke to one or two hubs, plus direct tunnels only between sites that talk to each other heavily. Check the tunnel ceiling on the datasheet of the smallest edge model before you standardise on it.

Security inspection sized at the wrong place

When branch internet traffic is sent back to a hub for inspection, the hub firewall carries every site's browsing on top of its own. Size it on throughput with inspection switched on, as explained in sizing a firewall for a UAE SME, and decide which traffic breaks out locally at each site instead.

Licences that can stop traffic when they lapse

Most SD-WAN platforms are subscriptions. Meraki's licensing FAQ says that out of compliance, you can no longer change the configuration and the products stop passing traffic to the internet. Meraki's MX licensing page also notes that Enterprise licensed organisations cannot mix licence editions, and that analytics such as VoIP Health and WAN Health come with the Secure SD-WAN Plus tier. Pick the tier for every site at the start, and put one renewal date in the finance calendar.

What to settle before asking for a quote

  1. A site list with location, headcount and the circuits each site has or will order, including which carrier and whether a static address is available.
  2. The traffic pattern: which sites talk to which, where the servers and cloud services sit, and whether voice crosses the WAN.
  3. Topology: hub and spoke, full mesh, or a mix, with the resulting tunnel count per edge device.
  4. Throughput per site with inspection on, and whether a hub is inspecting other sites' traffic.
  5. Reaction time you need, written as seconds, and who tunes the platform to reach it.
  6. Licence tier and term for every device, aligned to one renewal date.
  7. High availability at the hub and a cold spare edge device for the sites that cannot wait for a replacement.

Sourcing the hardware

Codeeo Tech is a hardware supplier, not an SD-WAN integrator or managed service provider, so the design and tuning above belong to your team or your integrator. What we supply are the edge platforms: Cisco Catalyst 8000 series edge platforms and Cisco Meraki appliances, and Fortinet FortiGate firewalls, whose FortiOS includes SD-WAN with performance SLA monitoring. Every item is priced on request. Send the site list and bill of materials from the checklist through the contact page and ask for a quotation against it, including licence terms for each device.

Cover photo: View of Dubai, the Dubai Water Canal, Business Bay and Ras Al Khor from the International Space Station (ISS065-E-74310) by the Earth Science and Remote Sensing Unit, NASA Johnson Space Center, via Wikimedia Commons (Public domain).