SD-WAN Network Architecture
A full-stack view of Nepean Networks’ SD-WAN architecture β from customer CPE through cloud firewalls to the global management plane.
Click any node to explore its capabilities.
Antares Management Plane
SD-WAN Edge Routers
SecureConnect Firewall
CPE / SD-WAN Nodes
Customer Sites
Partner Space β Multi-Tenant SD-WAN
Routing Group A β e.g. Australia Β· Singapore Β· Japan
β¬ internet gateway
Routing Group B β e.g. US East Β· US West Β· Europe
β¬ internet gateway
⬑ full mesh
π
Internet
π₯
Cloud Firewall A
OPNsense Β· Clavister Β· FGT
// internet gateway Β· APAC
π₯
Cloud Firewall B
OPNsense Β· Clavister Β· FGT
// internet gateway Β· US/EU
β‘
SD-WAN Edge Router A1
Sydney PoP
// agg-a1.au
β‘
SD-WAN Edge Router A2
Singapore PoP
// agg-a2.sg
β‘
SD-WAN Edge Router B1
Dallas / NYC PoP
// agg-b1.us
β‘
SD-WAN Edge Router B2
EU / Amsterdam PoP
// agg-b2.eu
π₯οΈ
Antares Management
Server
Server
ZTP Β· NOC Β· Alerting Β· SSO
// management plane
Last-Mile ISP Links β NBN Β· 4G/5G Β· Fibre Β· DSL Β· Satellite
π¦
Nepean SD-WAN Node
Site A
Site A
Juggler Β· Illuminate Β· ZTP
π‘οΈ
Firewall VM (optional)Clavister Β· pfSense Β· OPNsense Β· MikroTik Β· OpenWrt
// Head Office Β· βΆ click
π¦
Nepean SD-WAN Node
Site B
Site B
QoS Β· Per-pkt Β· Compression
π‘οΈ
Firewall VM (optional)Clavister Β· pfSense Β· OPNsense Β· MikroTik Β· OpenWrt
// Branch Office Β· βΆ click
π¦
Nepean SD-WAN Node
Site C
Site C
SD-WAN Β· /32 IP Β· Bi-dir QoS
// Intl Branch Β· βΆ click
π¦
Nepean SD-WAN Node
Site D
Site D
GDPR Β· SD-WAN Β· Failover
// EU Branch Β· βΆ click
π₯οΈπ»π±
LAN Devices
// LAN β Site A
π₯οΈπ»π±
LAN Devices
// LAN β Site B
π₯οΈπ»π±
LAN Devices
// LAN β Site C
π₯οΈπ»π±
LAN Devices
// LAN β Site D
Traffic Flow
Internet egress
FW gateway
Management / control
Full mesh (Agg β Agg)
Bonded SD-WAN tunnel
Customer / LAN edge
Node Types
Cloud Firewall (GW)
Aggregation Server
Nepean SD-WAN Node
Firewall VM (inside node)
Customer LAN
π¦
Nepean SD-WAN Node
// Debian Β· OpenSUSE Β· x86 Β· ARM
πSecure Connect
- Remote access to upstream devices (modems, routers, ONTs)
- Access downstream LAN devices β printers, VoIP phones, cameras
- RDP / VNC to workstations & servers without VPN client
- Browser-based terminal, no agent required on target device
- Session logging & audit trail per user
π»SSH Terminal Access
- Full in-browser SSH to the SD-WAN node via Antares
- No inbound firewall rules or public IP required
- Role-based access β MSP vs customer permissions
- Restricted shell mode for read-only diagnostics
- Run diagnostic commands: ping, traceroute, iftop, tcpdump
β‘Sub-Second Failover
- Bonds 2β4 ISP legs simultaneously (active-active)
- <300ms detection & re-routing on link failure
- Per-packet load balancing across all live legs
- Automatic leg weighting by latency & loss
- Red-Blue tree packet reordering for smooth failover
πAdvanced Routing
- SD-WAN private mesh β direct site-to-site without internet
- Policy-based routing by application, DSCP, or source IP
- QoS β bi-directional traffic shaping & prioritisation
- VLAN support β multiple LAN segments per node
- Static, OSPF & BGP peering support
- Elastic /32 public IP per site via SD-WAN Edge Router NAT
π‘οΈOptional Firewall VM β Deployed & Managed via Antares
Clavister
pfSense
OPNsense
MikroTik
OpenWrt
+ more
- Runs inside the node via QEMU/KVM β no extra hardware
- Zero-touch deploy from Antares β no truck roll
- NAT, VLAN segmentation, stateful inspection
- IDS/IPS, captive portal, DNS filtering
- Full remote lifecycle: deploy, configure, upgrade
- Physical firewall also supported downstream of node
πIlluminate β Deep Packet Inspection
- Real-time application & protocol classification
- Per-application bandwidth usage breakdown
- Top talkers β by host, IP, application
- Historical DPI data retention & trend graphs
- Exportable reports for customer visibility
πAlerts β DPI & Connection
- DPI-based alerts β unusual application behaviour
- Bandwidth threshold alerts per application or total
- Link down / leg failure alerts (email, webhook)
- High latency & packet loss threshold alerts
- Customisable per-tenant alert rules in Antares
π‘Broadband Circuit Telemetry
- Per-leg latency, jitter & packet loss β live & historical
- Real-time throughput per ISP circuit
- MOS score tracking for VoIP quality monitoring
- Leg state: active, degraded, failed, standby
- ISP-level outage detection & duration logging
- 95th percentile bandwidth reporting for billing
Antares manages all features above remotely Β· No truck roll required Β· Multi-tenant Β· White-label ready