In an SD-WAN, what do the central controllers do, and how does a new branch edge provision itself through zero-touch provisioning?
answer
- management, control and data planes
- controllers stay off the data path
- identity registered before shipping
- bootstrap address, then redirect
- last-known state when controllers vanish
basics
~20 sControllers hold policy and distribute routes, tunnel endpoints and keys to edges, but user traffic normally flows edge to edge; zero-touch provisioning lets an unconfigured edge get an address, prove a pre-registered identity and download its site configuration.
solid answer
~50 sSD-WAN splits the work into planes. An **orchestrator** (management plane) is where templates, per-application policy and monitoring live. **Controllers** (control plane) authenticate edges, collect each site's prefixes and tunnel endpoints, and redistribute them with keys and policy, so edges peer with controllers rather than with every other edge. The **edges** (data plane) build the tunnels and forward traffic; user packets normally never cross a controller. **Zero-touch provisioning** works because the device's serial number or certificate is registered against a site before it ships: at the store it takes an address on a transport by DHCP, contacts a bootstrap service whose address is typically built into its software, proves its identity, is redirected to its organisation's controllers and pulls its configuration. If every controller later becomes unreachable, edges typically keep forwarding on last-known state but cannot accept changes or new peers.
go deeper
Recall the three roles: orchestrator for policy and templates, controllers for routes and keys, edges for forwarding. Know that zero-touch means plug in and the box configures itself.
Walk the zero-touch sequence: address by DHCP, bootstrap contact, certificate, redirect, configuration download, tunnels up. Explain why controllers stay off the data path.
Name where zero-touch fails, such as static addresses, captive portals or MPLS-only ports, and what edges keep doing when every controller is unreachable.
Weigh central control against the new dependency it creates: controller redundancy, reachability over several transports, key lifetimes and inventory hygiene become part of WAN availability.
## Three planes, three jobs No IETF standard defines SD-WAN, but implementations converge on the same division of labour. The words below describe that shared architecture. | Plane | Component | What it does | |---|---|---| | Management | **Orchestrator** | Holds device inventory, configuration templates, per-application policy, dashboards and logs | | Control | **Controllers** | Authenticate edges; collect and redistribute site prefixes, tunnel endpoints, keys and policy | | Data | **Edges** | Build tunnels over every transport, measure them, classify traffic and forward it | The control plane resembles a route reflector in spirit: each edge keeps a session to a small number of controllers rather than to every other edge. The controllers tell each edge which other edges exist, at which transport addresses, with which keys, and which private prefixes sit behind them. The edge then builds tunnels directly to its peers. - **Controllers are normally off the data path.** A store-to-hub voice call travels edge to edge through a tunnel; the controller only told both edges how to build it. - **Policy is central, enforcement is local.** An operator writes one rule, for example payment traffic may use MPLS or LTE but never guest broadband, and the controllers push it to every edge, which enforces it on each packet. - **Keys can be distributed centrally.** Some designs let controllers hand out tunnel keys instead of running a full pairwise key exchange between every two edges; the key-exchange protocols themselves are a separate subject. ## Zero-touch provisioning, step by step **Zero-touch provisioning (ZTP)** means a person with no networking skills can plug the box in and walk away. The sequence below is common; the details, including how the bootstrap service is found, are implementation choices. 1. **Before shipping**, the device's serial number and its factory-installed certificate are entered in the orchestrator's inventory and bound to a site, with that site's values (prefixes, circuit types, policy template). 2. **At the store**, staff connect the transports and power the device on. 3. The edge obtains a **transport address**, usually by DHCP on a broadband or LTE port, and reaches the internet. 4. It contacts a **bootstrap or redirect service** at a name or address built into its software image, authenticating with its certificate. 5. The bootstrap service recognises the device and **redirects** it to its own organisation's orchestrator and controllers. 6. Edge and controllers **authenticate each other**; the edge downloads its configuration and policy. 7. The edge joins the control plane, learns its peers and keys, builds its tunnels and starts forwarding. ## Where zero-touch breaks - **No automatic address.** A circuit that requires a static address, or a captive portal, stops step 3; a preloaded file or a technician is the fallback. - **No internet on the first port.** A store whose only working circuit is an MPLS VPN cannot reach an internet-hosted bootstrap service unless the carrier provides internet access or a reachable on-premises bootstrap exists. - **Wrong box at the wrong store.** Identity is bound to a site, so swapping two devices in shipping applies the wrong store's configuration; inventory hygiene is part of the design. - **A stolen device.** The certificate is the device's credential. Revoking it and removing it from the inventory is what stops a stolen box from joining. ## When the controllers disappear Because controllers are off the data path, losing them is not an instant outage. Implementations typically let edges keep forwarding on their last-known routes, tunnels and keys for a period, sometimes called headless operation. What stops working is everything that needs the control plane: - new stores cannot be provisioned; - policy and configuration changes cannot be pushed; - a tunnel that drops may not be rebuilt if it needs fresh information; - keys cannot be rotated, so tunnels eventually fail if the outage lasts longer than the key lifetime the implementation allows. For that reason controllers are deployed in redundant sets across sites or regions, and the controller's own reachability, over more than one transport, is part of the WAN design. The trade-off for central control is a new dependency: the WAN no longer depends only on circuits, but also on a software service that every edge must be able to reach.
- What happens to a store's running SD-WAN edge if every controller becomes unreachable?It typically keeps forwarding on its last-known routes, tunnels and keys, because controllers are off the data path. It cannot take policy changes, admit new peers or rotate keys, so a long outage eventually breaks tunnels as keys expire, on a timescale the implementation sets.
- Why can zero-touch provisioning fail at a store whose only working circuit is an MPLS VPN?The edge normally reaches an internet-hosted bootstrap service, and a private MPLS VPN does not reach the internet unless the carrier provides a gateway. A static-addressed port also defeats the automatic address step, so such stores need a reachable on-premises bootstrap, a preloaded file or a technician.
- How is a stolen SD-WAN edge prevented from joining the network?Its identity is a factory certificate tied to a serial number in the orchestrator's inventory. Removing the device from the inventory and revoking its certificate makes controllers refuse it, so possession of the hardware alone grants nothing.
Controllers work like air-traffic control: the tower clears routes and hands out instructions, but no passenger ever flies through the tower. If the tower goes silent, aircraft already flying continue on their cleared routes, while nothing new can be cleared until it returns.
saying these in an interview costs you the question
- Every new flow is sent to the controller to choose its path
- Controllers terminate all tunnels and relay traffic between stores
- Losing the controllers immediately stops all branch forwarding
- Zero-touch provisioning identifies the device by the public address it receives
- Zero-touch means no planning; any box can be shipped to any store