[](https://www.paloaltonetworks.com/?ts=markdown) * Sign In * Customer * Partner * Employee * [Login to download](https://www.paloaltonetworks.com/login?ts=markdown) * [Join us to become a member](https://www.paloaltonetworks.com/login?screenToRender=traditionalRegistration&ts=markdown) * EN * [USA (ENGLISH)](https://www.paloaltonetworks.com) * [AUSTRALIA (ENGLISH)](https://www.paloaltonetworks.com.au) * [BRAZIL (PORTUGUÉS)](https://www.paloaltonetworks.com.br) * [CANADA (ENGLISH)](https://www.paloaltonetworks.ca) * [CHINA (简体中文)](https://www.paloaltonetworks.cn) * [FRANCE (FRANÇAIS)](https://www.paloaltonetworks.fr) * [GERMANY (DEUTSCH)](https://www.paloaltonetworks.de) * [INDIA (ENGLISH)](https://www.paloaltonetworks.in) * [ITALY (ITALIANO)](https://www.paloaltonetworks.it) * [JAPAN (日本語)](https://www.paloaltonetworks.jp) * [KOREA (한국어)](https://www.paloaltonetworks.co.kr) * [LATIN AMERICA (ESPAÑOL)](https://www.paloaltonetworks.lat) * [MEXICO (ESPAÑOL)](https://www.paloaltonetworks.com.mx) * [SINGAPORE (ENGLISH)](https://www.paloaltonetworks.sg) * [SPAIN (ESPAÑOL)](https://www.paloaltonetworks.es) * [TAIWAN (繁體中文)](https://www.paloaltonetworks.tw) * [UK (ENGLISH)](https://www.paloaltonetworks.co.uk) * ![magnifying glass search icon to open search field](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/search-black.svg) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [What's New](https://www.paloaltonetworks.com/resources?ts=markdown) * [Get Support](https://support.paloaltonetworks.com/SupportAccount/MyAccount) * [Under Attack?](https://start.paloaltonetworks.com/contact-unit42.html) ![x close icon to close mobile navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/x-black.svg) [![Palo Alto Networks logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)](https://www.paloaltonetworks.com/?ts=markdown) ![magnifying glass search icon to open search field](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/search-black.svg) * [](https://www.paloaltonetworks.com/?ts=markdown) * Products ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Products [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [AI Security](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise Device Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical Device Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [OT Device Security](https://www.paloaltonetworks.com/network-security/ot-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex AgentiX](https://www.paloaltonetworks.com/cortex/agentix?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Exposure Management](https://www.paloaltonetworks.com/cortex/exposure-management?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Cortex Advanced Email Security](https://www.paloaltonetworks.com/cortex/advanced-email-security?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Unit 42 Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * Solutions ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Solutions Secure AI by Design * [Secure AI Ecosystem](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [Secure GenAI Usage](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) Network Security * [Cloud Network Security](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Data Center Security](https://www.paloaltonetworks.com/network-security/data-center?ts=markdown) * [DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Intrusion Detection and Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Device Security](https://www.paloaltonetworks.com/network-security/device-security?ts=markdown) * [OT Security](https://www.paloaltonetworks.com/network-security/ot-device-security?ts=markdown) * [5G Security](https://www.paloaltonetworks.com/network-security/5g-security?ts=markdown) * [Secure All Apps, Users and Locations](https://www.paloaltonetworks.com/sase/secure-users-data-apps-devices?ts=markdown) * [Secure Branch Transformation](https://www.paloaltonetworks.com/sase/secure-branch-transformation?ts=markdown) * [Secure Work on Any Device](https://www.paloaltonetworks.com/sase/secure-work-on-any-device?ts=markdown) * [VPN Replacement](https://www.paloaltonetworks.com/sase/vpn-replacement-for-secure-remote-access?ts=markdown) * [Web \& Phishing Security](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) Cloud Security * [Application Security Posture Management (ASPM)](https://www.paloaltonetworks.com/cortex/cloud/application-security-posture-management?ts=markdown) * [Software Supply Chain Security](https://www.paloaltonetworks.com/cortex/cloud/software-supply-chain-security?ts=markdown) * [Code Security](https://www.paloaltonetworks.com/cortex/cloud/code-security?ts=markdown) * [Cloud Security Posture Management (CSPM)](https://www.paloaltonetworks.com/cortex/cloud/cloud-security-posture-management?ts=markdown) * [Cloud Infrastructure Entitlement Management (CIEM)](https://www.paloaltonetworks.com/cortex/cloud/cloud-infrastructure-entitlement-management?ts=markdown) * [Data Security Posture Management (DSPM)](https://www.paloaltonetworks.com/cortex/cloud/data-security-posture-management?ts=markdown) * [AI Security Posture Management (AI-SPM)](https://www.paloaltonetworks.com/cortex/cloud/ai-security-posture-management?ts=markdown) * [Cloud Detection \& Response](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response?ts=markdown) * [Cloud Workload Protection (CWP)](https://www.paloaltonetworks.com/cortex/cloud/cloud-workload-protection?ts=markdown) * [Web Application \& API Security (WAAS)](https://www.paloaltonetworks.com/cortex/cloud/web-app-api-security?ts=markdown) Security Operations * [Cloud Detection \& Response](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response?ts=markdown) * [Security Information and Event Management](https://www.paloaltonetworks.com/cortex/modernize-siem?ts=markdown) * [Network Security Automation](https://www.paloaltonetworks.com/cortex/network-security-automation?ts=markdown) * [Incident Case Management](https://www.paloaltonetworks.com/cortex/incident-case-management?ts=markdown) * [SOC Automation](https://www.paloaltonetworks.com/cortex/security-operations-automation?ts=markdown) * [Threat Intel Management](https://www.paloaltonetworks.com/cortex/threat-intel-management?ts=markdown) * [Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Attack Surface Management](https://www.paloaltonetworks.com/cortex/cortex-xpanse/attack-surface-management?ts=markdown) * [Compliance Management](https://www.paloaltonetworks.com/cortex/cortex-xpanse/compliance-management?ts=markdown) * [Internet Operations Management](https://www.paloaltonetworks.com/cortex/cortex-xpanse/internet-operations-management?ts=markdown) * [Extended Data Lake (XDL)](https://www.paloaltonetworks.com/cortex/cortex-xdl?ts=markdown) * [Agentic Assistant](https://www.paloaltonetworks.com/cortex/cortex-agentic-assistant?ts=markdown) Endpoint Security * [Endpoint Protection](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Extended Detection \& Response](https://www.paloaltonetworks.com/cortex/detection-and-response?ts=markdown) * [Ransomware Protection](https://www.paloaltonetworks.com/cortex/ransomware-protection?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/cortex/digital-forensics?ts=markdown) [Industries](https://www.paloaltonetworks.com/industry?ts=markdown) * [Public Sector](https://www.paloaltonetworks.com/industry/public-sector?ts=markdown) * [Financial Services](https://www.paloaltonetworks.com/industry/financial-services?ts=markdown) * [Manufacturing](https://www.paloaltonetworks.com/industry/manufacturing?ts=markdown) * [Healthcare](https://www.paloaltonetworks.com/industry/healthcare?ts=markdown) * [Small \& Medium Business Solutions](https://www.paloaltonetworks.com/industry/small-medium-business-portfolio?ts=markdown) * Services ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Services [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Assess](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [AI Security Assessment](https://www.paloaltonetworks.com/unit42/assess/ai-security-assessment?ts=markdown) * [Attack Surface Assessment](https://www.paloaltonetworks.com/unit42/assess/attack-surface-assessment?ts=markdown) * [Breach Readiness Review](https://www.paloaltonetworks.com/unit42/assess/breach-readiness-review?ts=markdown) * [BEC Readiness Assessment](https://www.paloaltonetworks.com/bec-readiness-assessment?ts=markdown) * [Cloud Security Assessment](https://www.paloaltonetworks.com/unit42/assess/cloud-security-assessment?ts=markdown) * [Compromise Assessment](https://www.paloaltonetworks.com/unit42/assess/compromise-assessment?ts=markdown) * [Cyber Risk Assessment](https://www.paloaltonetworks.com/unit42/assess/cyber-risk-assessment?ts=markdown) * [M\&A Cyber Due Diligence](https://www.paloaltonetworks.com/unit42/assess/mergers-acquisitions-cyber-due-diligence?ts=markdown) * [Penetration Testing](https://www.paloaltonetworks.com/unit42/assess/penetration-testing?ts=markdown) * [Purple Team Exercises](https://www.paloaltonetworks.com/unit42/assess/purple-teaming?ts=markdown) * [Ransomware Readiness Assessment](https://www.paloaltonetworks.com/unit42/assess/ransomware-readiness-assessment?ts=markdown) * [SOC Assessment](https://www.paloaltonetworks.com/unit42/assess/soc-assessment?ts=markdown) * [Supply Chain Risk Assessment](https://www.paloaltonetworks.com/unit42/assess/supply-chain-risk-assessment?ts=markdown) * [Tabletop Exercises](https://www.paloaltonetworks.com/unit42/assess/tabletop-exercise?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) * [Respond](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Cloud Incident Response](https://www.paloaltonetworks.com/unit42/respond/cloud-incident-response?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/unit42/respond/digital-forensics?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond/incident-response?ts=markdown) * [Managed Detection and Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response?ts=markdown) * [Managed Threat Hunting](https://www.paloaltonetworks.com/unit42/respond/managed-threat-hunting?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) * [Transform](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [IR Plan Development and Review](https://www.paloaltonetworks.com/unit42/transform/incident-response-plan-development-review?ts=markdown) * [Security Program Design](https://www.paloaltonetworks.com/unit42/transform/security-program-design?ts=markdown) * [Virtual CISO](https://www.paloaltonetworks.com/unit42/transform/vciso?ts=markdown) * [Zero Trust Advisory](https://www.paloaltonetworks.com/unit42/transform/zero-trust-advisory?ts=markdown) [Global Customer Services](https://www.paloaltonetworks.com/services?ts=markdown) * [Education \& Training](https://www.paloaltonetworks.com/services/education?ts=markdown) * [Professional Services](https://www.paloaltonetworks.com/services/consulting?ts=markdown) * [Success Tools](https://www.paloaltonetworks.com/services/customer-success-tools?ts=markdown) * [Support Services](https://www.paloaltonetworks.com/services/solution-assurance?ts=markdown) * [Customer Success](https://www.paloaltonetworks.com/services/customer-success?ts=markdown) [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-unit-42.svg) UNIT 42 RETAINER Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Learn more](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) * Partners ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Partners NextWave Partners * [NextWave Partner Community](https://www.paloaltonetworks.com/partners?ts=markdown) * [Cloud Service Providers](https://www.paloaltonetworks.com/partners/nextwave-for-csp?ts=markdown) * [Global Systems Integrators](https://www.paloaltonetworks.com/partners/nextwave-for-gsi?ts=markdown) * [Technology Partners](https://www.paloaltonetworks.com/partners/technology-partners?ts=markdown) * [Service Providers](https://www.paloaltonetworks.com/partners/service-providers?ts=markdown) * [Solution Providers](https://www.paloaltonetworks.com/partners/nextwave-solution-providers?ts=markdown) * [Managed Security Service Providers](https://www.paloaltonetworks.com/partners/managed-security-service-providers?ts=markdown) * [XMDR Partners](https://www.paloaltonetworks.com/partners/managed-security-service-providers/xmdr?ts=markdown) Take Action * [Portal Login](https://www.paloaltonetworks.com/partners/nextwave-partner-portal?ts=markdown) * [Managed Services Program](https://www.paloaltonetworks.com/partners/managed-security-services-provider-program?ts=markdown) * [Become a Partner](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=becomepartner) * [Request Access](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=requestaccess) * [Find a Partner](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerlocator) [CYBERFORCE CYBERFORCE represents the top 1% of partner engineers trusted for their security expertise. Learn more](https://www.paloaltonetworks.com/cyberforce?ts=markdown) * Company ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Company Palo Alto Networks * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Management Team](https://www.paloaltonetworks.com/about-us/management?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com) * [Locations](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Ethics \& Compliance](https://www.paloaltonetworks.com/company/ethics-and-compliance?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Military \& Veterans](https://jobs.paloaltonetworks.com/military) [Why Palo Alto Networks?](https://www.paloaltonetworks.com/why-paloaltonetworks?ts=markdown) * [Precision AI Security](https://www.paloaltonetworks.com/precision-ai-security?ts=markdown) * [Our Platform Approach](https://www.paloaltonetworks.com/why-paloaltonetworks/platformization?ts=markdown) * [Accelerate Your Cybersecurity Transformation](https://www.paloaltonetworks.com/why-paloaltonetworks/nam-cxo-portfolio?ts=markdown) * [Awards \& Recognition](https://www.paloaltonetworks.com/about-us/awards?ts=markdown) * [Customer Stories](https://www.paloaltonetworks.com/customers?ts=markdown) * [Global Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Trust 360 Program](https://www.paloaltonetworks.com/resources/whitepapers/trust-360?ts=markdown) Careers * [Overview](https://jobs.paloaltonetworks.com/) * [Culture \& Benefits](https://jobs.paloaltonetworks.com/en/culture/) [A Newsweek Most Loved Workplace "Businesses that do right by their employees" Read more](https://www.paloaltonetworks.com/company/press/2021/palo-alto-networks-secures-top-ranking-on-newsweek-s-most-loved-workplaces-list-for-2021?ts=markdown) * More ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) More Resources * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Unit 42 Threat Research](https://unit42.paloaltonetworks.com/) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Tech Insider](https://techinsider.paloaltonetworks.com/) * [Knowledge Base](https://knowledgebase.paloaltonetworks.com/) * [Palo Alto Networks TV](https://tv.paloaltonetworks.com/) * [Perspectives of Leaders](https://www.paloaltonetworks.com/perspectives/?ts=markdown) * [Cyber Perspectives Magazine](https://www.paloaltonetworks.com/cybersecurity-perspectives/cyber-perspectives-magazine?ts=markdown) * [Regional Cloud Locations](https://www.paloaltonetworks.com/products/regional-cloud-locations?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Security Posture Assessment](https://www.paloaltonetworks.com/security-posture-assessment?ts=markdown) * [Threat Vector Podcast](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/) * [Packet Pushers Podcasts](https://www.paloaltonetworks.com/podcasts/packet-pusher?ts=markdown) Connect * [LIVE community](https://live.paloaltonetworks.com/) * [Events](https://events.paloaltonetworks.com/) * [Executive Briefing Center](https://www.paloaltonetworks.com/about-us/executive-briefing-program?ts=markdown) * [Demos](https://www.paloaltonetworks.com/demos?ts=markdown) * [Contact us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) [Blog Stay up-to-date on industry trends and the latest innovations from the world's largest cybersecurity Learn more](https://www.paloaltonetworks.com/blog/) * Sign In ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Sign In * Customer * Partner * Employee * [Login to download](https://www.paloaltonetworks.com/login?ts=markdown) * [Join us to become a member](https://www.paloaltonetworks.com/login?screenToRender=traditionalRegistration&ts=markdown) * EN ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Language * [USA (ENGLISH)](https://www.paloaltonetworks.com) * [AUSTRALIA (ENGLISH)](https://www.paloaltonetworks.com.au) * [BRAZIL (PORTUGUÉS)](https://www.paloaltonetworks.com.br) * [CANADA (ENGLISH)](https://www.paloaltonetworks.ca) * [CHINA (简体中文)](https://www.paloaltonetworks.cn) * [FRANCE (FRANÇAIS)](https://www.paloaltonetworks.fr) * [GERMANY (DEUTSCH)](https://www.paloaltonetworks.de) * [INDIA (ENGLISH)](https://www.paloaltonetworks.in) * [ITALY (ITALIANO)](https://www.paloaltonetworks.it) * [JAPAN (日本語)](https://www.paloaltonetworks.jp) * [KOREA (한국어)](https://www.paloaltonetworks.co.kr) * [LATIN AMERICA (ESPAÑOL)](https://www.paloaltonetworks.lat) * [MEXICO (ESPAÑOL)](https://www.paloaltonetworks.com.mx) * [SINGAPORE (ENGLISH)](https://www.paloaltonetworks.sg) * [SPAIN (ESPAÑOL)](https://www.paloaltonetworks.es) * [TAIWAN (繁體中文)](https://www.paloaltonetworks.tw) * [UK (ENGLISH)](https://www.paloaltonetworks.co.uk) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [What's New](https://www.paloaltonetworks.com/resources?ts=markdown) * [Get support](https://support.paloaltonetworks.com/SupportAccount/MyAccount) * [Under Attack?](https://start.paloaltonetworks.com/contact-unit42.html) * [Demos and Trials](https://www.paloaltonetworks.com/get-started?ts=markdown) Search All * [Tech Docs](https://docs.paloaltonetworks.com/search) Close search modal [Deploy Bravely --- Secure your AI transformation with Prisma AIRS](https://www.deploybravely.com) [](https://www.paloaltonetworks.com/?ts=markdown) 1. [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) 2. [Cloud Security](https://www.paloaltonetworks.com/cyberpedia/cloud-security?ts=markdown) 3. [How to Execute an MPLS to SD-WAN Migration Step-by-Step](https://www.paloaltonetworks.com/cyberpedia/mpls-to-sd-wan-migration?ts=markdown) Table of contents * [Why do organizations switch from MPLS to SD-WAN?](#organizations) * [How is SD-WAN a better alternative to MPLS?](#sd-wan) * [What are the options for migration from MPLS to SD-WAN?](#migration) * [Should you use an MSP for your MPLS to SD-WAN migration?](#mpls) * [What are the MPLS to SD-WAN migration challenges you can expect?](#expect) * [Is there a middle ground between MPLS and SD-WAN?](#middle) * [If your organization is planning an MPLS to SD-WAN migration, is SASE worth considering?](#organization) * [How to create a successful MPLS to SD-WAN migration plan](#successful) * [MPLS to SD-WAN migration FAQs](#faqs) # How to Execute an MPLS to SD-WAN Migration Step-by-Step 5 min. read Table of contents * [Why do organizations switch from MPLS to SD-WAN?](#organizations) * [How is SD-WAN a better alternative to MPLS?](#sd-wan) * [What are the options for migration from MPLS to SD-WAN?](#migration) * [Should you use an MSP for your MPLS to SD-WAN migration?](#mpls) * [What are the MPLS to SD-WAN migration challenges you can expect?](#expect) * [Is there a middle ground between MPLS and SD-WAN?](#middle) * [If your organization is planning an MPLS to SD-WAN migration, is SASE worth considering?](#organization) * [How to create a successful MPLS to SD-WAN migration plan](#successful) * [MPLS to SD-WAN migration FAQs](#faqs) 1. Why do organizations switch from MPLS to SD-WAN? * [1. Why do organizations switch from MPLS to SD-WAN?](#organizations) * [2. How is SD-WAN a better alternative to MPLS?](#sd-wan) * [3. What are the options for migration from MPLS to SD-WAN?](#migration) * [4. Should you use an MSP for your MPLS to SD-WAN migration?](#mpls) * [5. What are the MPLS to SD-WAN migration challenges you can expect?](#expect) * [6. Is there a middle ground between MPLS and SD-WAN?](#middle) * [7. If your organization is planning an MPLS to SD-WAN migration, is SASE worth considering?](#organization) * [8. How to create a successful MPLS to SD-WAN migration plan](#successful) * [9. MPLS to SD-WAN migration FAQs](#faqs) ![How Do You Migrate From MPLs to SD-WAN?](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/video-thumbnail-how-do-you-migrate-from-mpls-to-sd-wan.png) close Executing a successful MPLS to SD-WAN migration is generally a seven-step process: 1. Assess your current network needs 2. Establish a performance baseline 3. Choose the right SD-WAN provider 4. Create a detailed migration plan 5. Execute the migration carefully 6. Test and monitor post-migration 7. Continuously monitor and optimize Migrating from MPLS to SD-WAN requires careful planning and execution to avoid disruptions and ensure optimal performance. ## Why do organizations switch from MPLS to SD-WAN? It's common knowledge that modern businesses need to be able to adapt quickly and run smoothly. Managing network infrastructure is no exception. But before [SD-WAN](https://www.paloaltonetworks.com/cyberpedia/what-is-sd-wan?ts=markdown) emerged to solve this problem, there was [multiprotocol label switching (MPLS).](https://www.paloaltonetworks.com/cyberpedia/mpls-what-is-multiprotocol-label-switching?ts=markdown) Historically, MPLS was favored because it's relatively reliable. Plus, it manages and prioritizes traffic flows pretty efficiently. MPLS emerged in the 1980s and 1990s, offering a more efficient way to manage and route traffic over vast networks. It became the standard for traditional WANs, known for reliability and [quality of service (QoS)](https://www.paloaltonetworks.com/cyberpedia/what-is-quality-of-service-qos?ts=markdown). The reason it's so reliable is because MPLS provides dedicated pathways for data. That's what ensures the predictable service levels. Which makes it useful for applications requiring stringent latency measures. ![The diagram titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/mpls-architecture.png "The diagram titled ") However, as cloud computing and SaaS applications grew in popularity in the 2000s and onward---combined with the integration of mobile and IoT devices---the limitations of MPLS started to become problematic. Today's organizations need a more flexible, cost-effective solution to handle the increased demand for bandwidth, not to mention the shift towards decentralized applications. Unfortunately, MPLS can be somewhat rigid and cost inefficient in the modern context. In particular, in a cloud-centric environment, MPLS can be very complex and expensive to manage. And that's because of the need for hardware installations at each site, plus bandwidth restrictions---which do not scale economically as data demands increase. This is where SD-WAN (software-defined wide area network) becomes an alternative worth considering. ![SD-WAN architecture diagram, featuring a central data center connected to four branch locations, represented as gray building icons. These connections are color-coded to indicate different types of internet connections: MPLS in red, cellular connections in green, and broadband in orange. Surrounding the central network diagram are logos of various internet and cloud services, such as AWS, Azure, Google, Dropbox, Salesforce, Workday, and YouTube, implying their integration or accessibility through this network architecture](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/SD-WAN-architecture.png "SD-WAN architecture diagram, featuring a central data center connected to four branch locations, represented as gray building icons. These connections are color-coded to indicate different types of internet connections: MPLS in red, cellular connections in green, and broadband in orange. Surrounding the central network diagram are logos of various internet and cloud services, such as AWS, Azure, Google, Dropbox, Salesforce, Workday, and YouTube, implying their integration or accessibility through this network architecture") SD-WAN introduces major flexibility and substantial cost-effectiveness when it comes to managing network traffic. Unlike MPLS, SD-WAN doesn't require physical infrastructure to reroute traffic. The adaptability is crucial for modern businesses that use a variety of cloud-based applications and services. For example: Consider a typical enterprise using multiple SaaS solutions across different regions. SD-WAN allows for dynamic path selection, which optimizes connectivity and performance by routing traffic through the most efficient paths. Like this: ![The diagram illustrates centralized management in SD-WAN. It shows an SD-WAN controller at the center, managing data flows between the MPLS network, the internet, and cloud services. On the left, a branch office connects to the SD-WAN controller through traditional WAN routers. The middle section displays various types of connectivity, including fiber, dedicated internet access, MPLS, and 4G, all managed by the SD-WAN controller. On the right, the HQ/DC/DR is also connected via traditional WAN routers. Control plane data paths are indicated by yellow dashed lines, while data plane paths are shown as solid red lines.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/dynamic-path-selection.png "The diagram illustrates centralized management in SD-WAN. It shows an SD-WAN controller at the center, managing data flows between the MPLS network, the internet, and cloud services. On the left, a branch office connects to the SD-WAN controller through traditional WAN routers. The middle section displays various types of connectivity, including fiber, dedicated internet access, MPLS, and 4G, all managed by the SD-WAN controller. On the right, the HQ/DC/DR is also connected via traditional WAN routers. Control plane data paths are indicated by yellow dashed lines, while data plane paths are shown as solid red lines.") This capability is vital for enhancing the digital experience of users and supporting real-time applications that are sensitive to latency. ***Further reading** : [What Is the Difference Between SD-WAN and MPLS?](https://www.paloaltonetworks.com/cyberpedia/sd-wan-vs-mpls?ts=markdown)* ## How is SD-WAN a better alternative to MPLS? ![Architecture diagram comparing](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/sd-wan-vs-mpls-architecture.png "Architecture diagram comparing ") SD-WAN addresses the limitations of MPLS by offering a solution that aligns with the demands of modern network environments, including: * Flexibility for modern \& remote workforces * Better cloud connectivity and application integration * Optimal performance across interconnected systems * Cost-effectiveness and simplified management * Decentralized and provider-independent networking Ultimately, SD-WAN supports the decentralized networks that modern enterprises operate. It accommodates the high variability in traffic that comes from services like video conferencing, streaming, and real-time collaboration tools. All of which have become commonplace in today's workplace---and are bandwidth intensive. ![The diagram titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/dynamic-path-selection-traffic-steering.png "The diagram titled ") As organizations push for greater digital transformation, the inherent scalability and flexibility offered by SD-WAN become increasingly more important. But the MPLS migration to SD-WAN isn't just about adopting new technology. The unique [benefits of SD-WAN](https://www.paloaltonetworks.com/cyberpedia/benefits-of-sd-wan?ts=markdown) allow enterprises to be substantially more agile in their network management. Plus, organizations are in a far better position to respond to network demand changes fast, not to mention opportunities for technological integration. ### Flexibility for modern \& remote workforces ![Diagram illustrating six benefits of using SD-WAN. The benefits are arranged in a circular flow around a central SD-WAN icon. The benefits are: 1. Multiple internet connections provide load balancing and failover for reliability. 2. Remote locations can securely access on-premises servers. 3. Work-from-home employees get the same speed and security as in-office employees. 4. Secure network connectivity enables work from anywhere. 5. Critical cloud and SaaS apps are always available. 6. Network admins can monitor and manage the network from anywhere.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/sd-wan-connecting-users-to-apps-services.png "Diagram illustrating six benefits of using SD-WAN. The benefits are arranged in a circular flow around a central SD-WAN icon. The benefits are: 1. Multiple internet connections provide load balancing and failover for reliability. 2. Remote locations can securely access on-premises servers. 3. Work-from-home employees get the same speed and security as in-office employees. 4. Secure network connectivity enables work from anywhere. 5. Critical cloud and SaaS apps are always available. 6. Network admins can monitor and manage the network from anywhere.") Nowadays, the modern workforce is increasingly remote. Employees are working from various locations such as their homes, co-working spaces, or even while traveling. *"According to [Deloitte](https://www2.deloitte.com/us/en/insights/industry/telecommunications/connectivity-mobile-trends-survey/2023/hybrid-work-challenges-statistics.html), 56% of employed adults work from home at least part of the time. Of these, 22% work fully from home, while 34% maintain a hybrid schedule, blending in-office and remote work. Hybrid workers, on average, spend 3 days in the office and 2.6 days working remotely."* Given the shift to a distributed workforce, traditional office-centric network setups are obviously no longer sufficient. Especially traditionally rigid ones that are often associated with MPLS. Businesses have to be able to adapt quickly to changing network demands. And they also need to be able to provide secure, yet reliable access to corporate resources from anywhere. SD-WAN adjusts dynamically to support diverse and shifting user demands without the need for complex configurations. Plus, the rise in cloud-based applications, video conferencing, and collaborative tools requires flexible, scalable network solutions. SD-WAN works well because it can handle fluctuating traffic and provide seamless connectivity, regardless of where employees are working. ### Better cloud connectivity and application integration ![The image titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/sd-wan-cloud-connectivity.png "The image titled ") With a majority of applications now being cloud-based, SD-WAN's ability to offer improved and direct cloud connectivity is increasingly important. *"SaaS (software as a service) applications continues to be the largest category of public cloud services, accounting for approximately 45% of the global cloud market in 2023. The global public cloud services market itself grew by nearly 20% in 2023, reflecting widespread adoption across industries, [IDC](https://www.idc.com/getdoc.jsp?containerId=prUS52343224) reported​."* Direct access substantially improves cloud application performance and efficiency. MPLS, on the other hand, tends to fall short here. Mostly because its inherent design limitations weren't intended for cloud integration. SD-WAN's ability to integrate smoothly with cloud services and external applications supports distributed, modern organizations. Unlike MPLS, which may require special arrangements to connect to cloud infrastructures, SD-WAN facilitates direct and efficient cloud connections. Which equals streamlined access and improved overall network performance. ### Optimal performance across interconnected systems Modern applications are often highly interconnected, which creates new challenges for network performance. SD-WAN's adaptability plays a crucial role in addressing these challenges. It allows businesses to dynamically route traffic based on real-time needs, ensuring smooth performance across interconnected systems and applications. This flexibility helps prevent the bottlenecks commonly seen with traditional MPLS setups, especially in complex digital environments where cloud-based applications and real-time collaboration tools are increasingly common. With SD-WAN, networks can adjust automatically to shifting traffic demands, making it easier to maintain optimal performance for critical business processes. By accommodating the dynamic nature of modern applications, SD-WAN ensures that network resources are used efficiently, improving overall application performance and user experience. ### Cost-effectiveness and simplified management ![Image titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/how-sd-wan-reduces-networking-costs.png "Image titled ") SD-WAN offers a more budget-friendly solution by reducing the need for the proprietary hardware required with MPLS. It also uses existing internet connections, which lowers both installation and operational costs. Also: SD-WAN simplifies network management through automation, streamlining tasks like traffic routing and policy updates. This allows businesses to scale easily. Adding new sites or adopting new technologies is fairly simple, and certainly without the complexity often associated with MPLS setups. ***Note:** While it's true that SD-WAN can help organizations save money on network costs, savings aren't always guaranteed. The cost of MPLS networks and diverse broadband options vary by location. Plus, initial investments can be substantial, and network complexity along with ongoing management costs can offset savings. The geographical distribution of your locations can influence the complexity and cost of implementing an SD-WAN solution that meets your network connectivity needs.* ***Further reading:** [How Much Does SD-WAN Cost?](https://www.paloaltonetworks.com/cyberpedia/how-much-does-sdwan-cost?ts=markdown)* ### Decentralized and provider-independent networking ![Diagram titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/sd-wan-multiple-transport-services.png "Diagram titled ") SD-WAN offers independence from traditional service providers. Businesses can configure their WAN based on specific needs without being tied to a single provider. The flexibility ensures that businesses can choose the most suitable, cost-effective service options available. That's a stark contrast to MPLS, which often locks organizations into long-term contracts with specific carriers. [![Teal CTA banner showing an icon with a dollar sign and SD-WAN text, accompanied by the message,Find out the potential ROI your organization could achieve with SD-WAN.Below is a button labeled Try the ROI calculator.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/roi-sd-wan.png)](https://tei.forrester.com/go/paloalto/prismasase/index.html?lang=en-us) ## What are the options for migration from MPLS to SD-WAN? When migrating from MPLS to SD-WAN, businesses have several strategies to choose from: * Augmentation * Phased * Rip-and-replace The choice of migration strategy really depends on a company's specific needs and network structure. Each approach comes with its own set of pros and cons and varies in complexity and impact. Let's take a look at the details of each. ### Augmentation MPLS to SD-WAN migration ![Architecture diagram titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/augmentation-mpls-to-sd-wan-migration.png "Architecture diagram titled ") This option involves running MPLS and SD-WAN side-by-side. Essentially, the existing MPLS network is maintained, while SD-WAN is introduced gradually to handle specific traffic or applications. This migration approach is similar to the concept of a hybrid cloud, where both private and public cloud environments coexist. In this scenario, MPLS is still used for critical traffic, such as voice and video, while SD-WAN manages less sensitive traffic. This way, businesses can gradually introduce SD-WAN without totally abandoning MPLS infrastructure. It tends to be beneficial for organizations who are more focused on optimizing costs and performance while retaining MPLS for certain tasks. ### Rip-and-replace MPLS to SD-WAN migration ![Architecture diagram titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/rip-and-replace-mpls-to-sd-wan-migration.png "Architecture diagram titled ") A rip-and-replace migration is exactly what it sounds like: organizations completely replace their MPLS circuits with SD-WAN technology. This option is generally pursued by organizations looking to fully embrace SD-WAN and move away from the high costs of MPLS connections. By switching completely to SD-WAN, businesses can reduce the expenses associated with MPLS while improving flexibility and scalability. However, this method does require very careful planning to ensure a smooth transition and avoid any disruptions in network performance. ### Phased MPLS to SD-WAN migration ![Architecture diagram titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/phased-mpls-to-sd-wan-migration.png "Architecture diagram titled ") A phased migration allows businesses to gradually migrate their remote sites or locations to SD-WAN. It starts by migrating the less critical sites first, which gives IT teams the opportunity to identify and resolve any issues early on. As more locations move over to SD-WAN, any obstacles that arise can be addressed. This generally makes for a smoother transition for the critical sites toward the end of the process. This method is ideal for businesses that prefer taking it a step at a time. It's worth noting that a phased migration from MPLS to SD-WAN does generally allow for better control and troubleshooting throughout the process. ## Should you use an MSP for your MPLS to SD-WAN migration? Deciding whether to use a managed service provider (MSP) for your MPLS to SD-WAN migration depends on your organization's needs, resources, and expertise. Either way, migrating from MPLS to SD-WAN is a big transition. It involves shifting from hardware-dependent connections to software-driven networking. And the process can be complex. MSPs can make the process more efficient and less overwhelming. But they come with a level of dependency that may not be suitable for everyone. An MSP can potentially help simplify this transition by guiding you through the technical steps and helping you avoid potential pitfalls. But is it the right choice for your organization? Let's break it down. If your network team has limited experience with SD-WAN, an MSP might be a good fit. Reputable MSPs bring a wealth of knowledge and expertise in network management. Which means they can handle the setup, configuration, and day-to-day management of your new SD-WAN system. So if you do have an internal network team, they can focus on other important tasks. ![Architecture diagram illustrating managed SD-WAN architecture. The left section shows a](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/managed-sd-wan.png "Architecture diagram illustrating managed SD-WAN architecture. The left section shows a ") MSPs also have access to the latest technology and can recommend solutions that fit your specific business needs. Another consideration is vendor neutrality. MSPs often act as a middleman between businesses and SD-WAN vendors. They can evaluate your network requirements and recommend a solution that fits your infrastructure and budget. While SD-WAN vendors are equally capable of supporting a new SD-WAN customer, the MSP approach may be more comfortable for some organizations who prefer to evaluate multiple options simultaneously from a vendor neutral perspective. Cost is an additional factor. For some organizations, MSPs can help reduce costs by outsourcing SD-WAN management versus hiring additional full-time network personnel. This can be financially helpful to businesses that don't have the resources to build a dedicated in-house team. If you partner with an MSP for your MPLS to SD-WAN migration, you can avoid the expense of extra hires while still benefiting from expert network management. However, relying on an MSP can also have some downsides. For instance, you'll be depending on a third-party provider for your network operations. Which means that any changes, updates, or troubleshooting will need to go through the MSP, and that could introduce delays. So if your business requires more direct control over network operations, then an in-house approach might be preferable. You'll have full control over the network---but may need to invest in training or hiring staff with the right expertise. Weigh the pros and cons carefully to determine the best path forward for your migration. ***Further reading:*** * *[What Is Managed SD-WAN?](https://www.paloaltonetworks.com/cyberpedia/what-is-managed-sdwan?ts=markdown)* \*\* [What Are Managed SASE Services?](https://www.paloaltonetworks.com/cyberpedia/what-are-managed-sase-services?ts=markdown)\* ## What are the MPLS to SD-WAN migration challenges you can expect? ![Graphic titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/mpls-to-sd-wan-migration-challenges.png "Graphic titled ") Migrating from MPLS to SD-WAN is a major commitment. As with any major infrastructure shift, there are challenges that you can expect to encounter along the way. The good news is that understanding the hurdles upfront can help in planning and executing a smoother migration. ### Hardware compatibility issues One challenge you may face during the migration is compatibility with your current hardware. Plenty of businesses have legacy equipment that isn't optimized for SD-WAN. **For example:** Older routers and switches might not support necessary updates or have the processing power to handle SD-WAN traffic. This could mean additional expenses to upgrade or retrofit your [SD-WAN hardware](https://www.paloaltonetworks.com/cyberpedia/what-is-an-sdwan-appliance?ts=markdown). On the other hand, if you choose not to upgrade, you may experience issues with network performance or stability. ### Bandwidth variability SD-WAN relies on public internet connections. Which means bandwidth can fluctuate depending on network congestion and ISP performance. MPLS, by contrast, offers more predictable, guaranteed bandwidth. So, with SD-WAN, careful planning is needed to ensure critical applications get the resources they need. If not managed well, your network performance could suffer during peak times, affecting operations. ### Security considerations When moving from MPLS to SD-WAN, security becomes a higher priority. MPLS uses private, controlled paths, while SD-WAN leverages the public internet. This exposure means you'll need to focus more on encryption and security features to protect your data. Integrating next-gen firewalls and other security measures is critical. However, balancing these security layers with network performance can be tricky. ### Deployment complexity Deploying SD-WAN can be tricky. It's worth noting that [zero touch provisioning (ZTP)](https://www.paloaltonetworks.com/cyberpedia/what-is-zero-touch-provisioning-ZTP?ts=markdown) is designed to simplify the process. But setting it up correctly can be complex. A lot depends on the initial configuration. Especially for organizations with multiple locations. You'll also need to retrain your IT and/or network staff to manage the new system. In short, even though ZTP reduces manual setup later, the early stages of deployment require careful planning. ### Network policy configuration SD-WAN offers the flexibility to prioritize different types of traffic. Which is great. But it also requires setting up detailed policies to ensure your critical applications get the bandwidth they need. **For example**: You might need to prioritize video conferencing over email traffic. Creating these policies can be a challenge, particularly in larger, more complex networks. The key is balancing your bandwidth across all applications without causing disruptions. ### Skill gaps in network teams SD-WAN technology is different from MPLS. Which means your network team will likely need training on the new system. Without this knowledge, migration could slow down, and troubleshooting issues may become more difficult. In some cases, it might be necessary to bring in outside expertise or rely on a managed service provider (MSP) for support. And that adds time and potential costs to the project. ### Monitoring and visibility As explained, SD-WAN paths are dynamic. They can change in real-time based on traffic conditions. Traditional monitoring tools might not offer the level of detail needed to track these changes effectively. So, ensuring that your IT team has access to advanced monitoring tools is essential. Otherwise, visibility gaps could leave you in the dark about performance issues until they start to affect operations. ## Is there a middle ground between MPLS and SD-WAN? Yes, there are ways to achieve a middle ground between MPLS and SD-WAN. One particular method, known as hybrid SD-WAN, combines SD-WAN technology with traditional MPLS by integrating it with other connection types like broadband and LTE to create a versatile, efficient network architecture. ![Image titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/hybrid-sd-wan-components.png "Image titled ") It tends to be a good fit for organizations that still depend on MPLS for critical applications but want to add the flexibility and cost savings that SD-WAN offers. Here's how hybrid SD-WAN works: ![Hybrid SD-WAN architecture diagram. It includes SD-WAN edges at branch sites, a central SD-WAN orchestrator, and SD-WAN gateways. The connections are established via public internet and private network/MPLS. The dynamic multipath optimization is indicated, showing the optimization process between the paths. The diagram also depicts connections to enterprise data centers via SD-WAN gateways and on-premise SD-WAN edges, highlighting the hybrid nature of the network.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/hybrid-sd-wan-works.png "Hybrid SD-WAN architecture diagram. It includes SD-WAN edges at branch sites, a central SD-WAN orchestrator, and SD-WAN gateways. The connections are established via public internet and private network/MPLS. The dynamic multipath optimization is indicated, showing the optimization process between the paths. The diagram also depicts connections to enterprise data centers via SD-WAN gateways and on-premise SD-WAN edges, highlighting the hybrid nature of the network.") SD-WAN acts as an overlay, increasing network flexibility and control by using software to manage virtual layers over existing physical networks. This allows organizations to dynamically direct and reroute traffic based on the specific requirements of different applications. MPLS, on the other hand, serves as the underlay, offering reliable and stable connections crucial for high-priority or sensitive data transfers. Keeping MPLS within a hybrid model ensures high-performance connections for tasks that need consistent bandwidth or low latency, like critical applications. This hybrid approach enables the physical infrastructure to reliably support essential business functions. ***Further reading** : [What Is Hybrid SD-WAN?](https://www.paloaltonetworks.com/cyberpedia/what-is-hybrid-sdwan?ts=markdown)* ## If your organization is planning an MPLS to SD-WAN migration, is SASE worth considering? If your organization is planning an MPLS to SD-WAN migration, SASE is absolutely worth considering before you move forward. When planning an SD-WAN migration of any kind, it's important to think about whether your organization's network security needs are evolving as well. **[Secure access service edge (SASE)](https://www.paloaltonetworks.com/cyberpedia/what-is-sase?ts=markdown)** combines SD-WAN with cloud-native security, including features like secure web gateways, firewalls, and zero-trust network access. ![Diagram titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/Components-of-sase.png "Diagram titled ") While SD-WAN optimizes network performance, SASE takes it a step further by integrating both networking and security into a single service. ![SASE architecture diagram, showing](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/sase-architecture.png "SASE architecture diagram, showing ") For organizations that want a future-proof solution, are managing decentralized workforces, and/or are cloud first, SASE could be a better long-term option. It definitely offers a more comprehensive approach to network and security. Especially for businesses looking to streamline management and security enforcement across all locations and users. ***Further reading** : [SASE vs. SD-WAN: What's the Difference?](https://www.paloaltonetworks.com/cyberpedia/sd-wan-vs-sase?ts=markdown)* [![Teal CTA banner featuring an icon of a hand holding the Palo Alto Networks Prisma SASE icon on the left. The text reads Get a personalized Prisma SASE demo.Below this text is a button labeled Request demo.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/prisma-sase-demo.png)](https://www.paloaltonetworks.com/company/request-demo?ts=markdown) ## How to create a successful MPLS to SD-WAN migration plan ![Image titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/mpls-to-sd-wan-migration-plan.png "Image titled ") Transitioning from MPLS to SD-WAN can bring significant benefits, but a successful migration requires careful planning and execution. A step-by-step plan will help you make sure you cover all the necessary components, avoid disruptions, and meet your network goals. Here's how to create a successful migration plan. ### Step 1: Assess your current network needs Start by evaluating your existing network setup. You'll need to document your bandwidth requirements, the applications you rely on, and where your users are located. This documentation will guide you in selecting the best SD-WAN solution. A clear view of your network topology---how your sites and components are connected---is essential. Additionally, take note of your business-critical applications so you can prioritize them during migration to minimize any disruption to operations. ***Tip** Always factor in the potential for future growth when determining the scalability and capacity requirements of your SD-WAN solution. To optimize costs effectively, you need to balance current needs with long-term objectives.* ### Step 2: Establish a performance baseline Before beginning your migration, it's important to benchmark your network's current performance. This means tracking metrics for both private and cloud-based applications, including: * Latency * Packet loss * User experience Like so: ![Image titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/network-baseline-example.png "Image titled ") These benchmarks will serve as your performance baseline, allowing you to measure improvements after SD-WAN implementation. A solid understanding of your current performance will also help you determine the effectiveness of the migration and ensure the project meets organizational expectations. ### Step 3: Choose the right SD-WAN provider ![The image titled](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/how-to-find-the-right-sd-wan-vendor.png "The image titled ") The provider you choose plays a critical role in the success of your migration. You'll need to evaluate various SD-WAN providers based on features, pricing, and support. Consider whether you need fully managed, co-managed, or self-managed services based on your IT team's expertise and your business needs. The right provider should be able to support your critical applications, ensure high performance, and offer the flexibility you need. ***Further reading:*** * *[Types of SD-WAN Deployment Models: A Complete Guide](https://www.paloaltonetworks.com/cyberpedia/sd-wan-deployment-models?ts=markdown)* \*\* [What Is SD-WAN as a Service (SD-WANaaS)?](https://www.paloaltonetworks.com/cyberpedia/what-is-sd-wanaas?ts=markdown)\* [![Teal CTA banner featuring an icon of a hand holding the Palo Alto Networks Prisma SASE icon on the left. The text reads Get a personalized Prisma SASE demo.Below this text is a button labeled Request demo.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/prisma-sdwan-demo.png)](https://www.paloaltonetworks.com/company/request-demo?ts=markdown) ### Step 4: Create a detailed migration plan Once you've assessed your network and chosen a provider, the next step is to create a detailed migration plan. Decide on the order of site migration. It's often a good idea to start with less critical locations to work out any potential issues before moving to more important sites. Coordination is also super important during this phase---so make sure to communicate your migration timeline to all relevant stakeholders, from your IT team to business users. Everyone needs to be adequately prepared for any changes. ### Step 5: Execute the MPLS to SD-WAN migration carefully During the MPLS migration to SD-WAN, it's important to proceed in a controlled, methodical manner. This may seem obvious, but it's easy to overlook smaller details that can cause disruptions if not properly managed Migrate one site at a time, ensuring that branch offices and internet access points are properly configured to avoid disruptions. ***Tip** As each site is moved from MPLS to SD-WAN, test the new setup thoroughly. This includes confirming that traffic is routed properly and key applications perform as expected. Testing as you go ensures that each migration step is successful before moving on to the next.* ### Step 6: Test and monitor post-migration After completing the migration, perform extensive testing to ensure the new network is functioning as expected across branch offices, data centers, and cloud applications. Compare the post-migration performance to the baseline you established earlier. This testing phase helps confirm that the SD-WAN solution is delivering the benefits you anticipated. ### Step 7: Continuously monitor and optimize Once your SD-WAN migration is complete, the process doesn't end. Continuous monitoring is essential to ensure your new SD-WAN solution continues to perform well. Monitor traffic patterns, identify any bottlenecks, and adjust policies as needed to optimize performance. Ongoing monitoring and optimization help you catch issues early and make necessary adjustments to maintain network health. [![Teal CTA banner featuring an icon of a hand holding the Palo Alto Networks Prisma SASE icon on the left. The text reads Get a personalized Prisma SASE demo.Below this text is a button labeled Request demo.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/mpls-to-sd-wan-migration/prisma-sd-wan-for-free.png)](https://start.paloaltonetworks.com/prisma-sd-wan-free-trial.html) ## MPLS to SD-WAN migration FAQs ### Why move from MPLS to SD-WAN? Organizations move from MPLS to SD-WAN for greater flexibility, scalability, and cost efficiency. SD-WAN supports modern cloud-based applications and decentralized workforces, allowing dynamic routing of traffic, which MPLS struggles to handle efficiently in today's network environments. ### What is the difference between SD-WAN and MPLS architecture? SD-WAN uses software to manage and route traffic dynamically over various connection types, while MPLS relies on dedicated, static paths. SD-WAN is more flexible, especially for cloud services, while MPLS offers more consistent, predictable performance for latency-sensitive applications. ### What is an SD-WAN migration? An SD-WAN migration involves transitioning network traffic from MPLS to an [SD-WAN architecture](https://www.paloaltonetworks.com/cyberpedia/sd-wan-architecture?ts=markdown). This shift allows businesses to dynamically manage traffic across multiple connection types, enhancing flexibility, reducing costs, and improving cloud connectivity without relying solely on dedicated MPLS circuits. ### What are the advantages of SD-WAN over MPLS? SD-WAN offers greater flexibility, cost savings, and simplified management. It improves cloud connectivity, dynamically routes traffic, and eliminates the need for expensive hardware. Unlike MPLS, SD-WAN adapts to varying traffic patterns and scales efficiently to meet modern network demands. Recommended for you [Forrester Total Economic Impact of Prisma SD-WAN Moving away from MPLS? Read the Forrester TEI for SD-WAN to see how SD-WAN is the solution.](https://start.paloaltonetworks.com/tei-spotlight-sd-wan) [Best Practices for SD-WAN Deployment Dive into best practices for a successful SD-WAN deployment.](https://www.paloaltonetworks.com/engage/sd-wan-lightspeed-on-demand/sd-wan-on-demand-videos/best-practices-sd-wan) [Branch of the Future with SD-WAN For Dummies^®^ Learn the four tenets of modern SD-WAN.](https://start.paloaltonetworks.com/branch-of-the-future-with-sd-wan-for-dummies.html) [National Automotive Retailer Replaces MPLS with Prisma SD-WAN, Gains Fast and Uninterrupted Connectivity See how AutoNation reduced telco costs by 25% with SD-WAN.](https://www.paloaltonetworks.com/customers/autonation?ts=markdown) ![Share page on facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/facebook-circular-icon.svg) ![Share page on linkedin](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/linkedin-circular-icon.svg) [![Share page by an email](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/email-circular-icon.svg)](mailto:?subject=How%20to%20Execute%20an%20MPLS%20to%20SD-WAN%20Migration%20Step-by-Step&body=MPLS%20to%20SD-WAN%20migration%20is%20a%20process%20including%20assessment%2C%20establishing%20performance%20baselines%2C%20vendor%20selection%2C%20planning%2C%20execution%2C%20testing%2C%20and%20monitoring.%20at%20https%3A//www.paloaltonetworks.com/cyberpedia/mpls-to-sd-wan-migration) Back to Top {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language