
SD-WAN Architecture & Troubleshooting Assistant
Design and troubleshoot SD-WAN deployments across multi-site networks
What You Can Do
This skill helps you architect resilient SD-WAN networks, diagnose connectivity issues across distributed sites, and optimize traffic policies for your branches. You can generate deployment architectures tailored to your topology, analyze traffic patterns for QoS optimization, and create comprehensive failover strategies with redundancy planning. It provides actionable troubleshooting workflows and vendor-agnostic configuration recommendations based on enterprise best practices.
Features
Create optimal hub-spoke, mesh, or hybrid topologies for your branch count and circuit mix
Model bandwidth flows, identify bottlenecks, and generate priority policies for voice, video, and data
Design primary/secondary link monitoring with automatic failover and load balancing logic
Generate vendor-agnostic policy templates for routers and SD-WAN controllers
Step-by-step diagnostics for latency, packet loss, tunnel failures, and asymmetric routing
Embed firewall rules, threat prevention, and compliance requirements into SD-WAN policies
Set realistic SLA targets, latency budgets, and monitoring thresholds for your environment
Design backup topologies with recovery time objectives (RTO) and failback automation
Example Output
Example 1: Multi-Site Architecture
Topology: Hub-and-Spoke with Mesh Overlay (15 branches)
- HQ (Hub): Dual ISP + MPLS fallback
- Branches 1-10: Primary ISP + MPLS backup
- Branches 11-15: Dual ISP active-active
Link Prioritization:
1. Primary ISP (SLA-monitored, 100ms threshold)
2. MPLS backup (cost optimized)
3. Cellular failover (branches 11-15)
QoS Policy:
- VoIP: 30Mbps reserved, <0.1% loss, <150ms latency
- Video: 50Mbps guaranteed, <150ms latency
- Data: Best-effort, >500ms threshold triggers failover
Example 2: Failover Troubleshooting (5 Steps)
Branch routing via MPLS backup instead of ISP:
- Check ISP link status (carrier outage verification)
- Validate local WAN interface (MAC table, CRC errors, duplex)
- Diagnose BGP/OSPF (route advertisements, metric mismatch, peer states)
- Test probe traffic (ICMP latency, route symmetry, jitter)
- Review SD-WAN policy (health thresholds, steering rules, failback triggers)
Example 3: Security Policy (POS Systems)
Ingress: Block external-to-POS, allow HQ management (encrypted only) Egress: Block POS-to-Internet (data loss prevention), allow payment gateway (whitelist IPs, TLS 1.2+) Encryption: All inter-site traffic IPsec, POS backup rate-limited to HQ
What's Included
- `SKILL.md`: Complete SD-WAN architecture and troubleshooting framework with decision trees
- `README.md`: Step-by-step user guide with real-world examples
- Network topology templates: Hub-spoke, mesh, and hybrid configurations
- QoS policy templates: Voice, video, and data prioritization policies
- Failover and redundancy checklists: Link health monitoring and automatic failback logic
- Troubleshooting workflows: Diagnostics for latency, packet loss, tunnel failures, and routing issues
- Security policy integration guide: Firewall rules, threat prevention, compliance mappings
- Performance benchmarking worksheet: SLA targets, latency budgets, capacity planning
- Configuration validation checklist: Common misconfigurations and remediation steps
Who It's For
- Network architects designing enterprise SD-WAN deployments and migrations
- Network engineers troubleshooting multi-site connectivity and performance issues
- IT directors planning SD-WAN adoption to replace or supplement MPLS networks
- Security engineers integrating firewalling and threat prevention into SD-WAN policies
- MSP engineers managing SD-WAN services across multiple customer environments
Best For
- Designing SD-WAN topologies for new branch rollouts or network consolidations
- Diagnosing and resolving failover, latency, and packet loss across WAN links
- Creating QoS and traffic prioritization policies for voice, video, and data applications
- Troubleshooting routing asymmetry, BGP/OSPF issues, and tunnel state failures
- Migrating from traditional MPLS to hybrid SD-WAN/MPLS architectures







