SD-WAN – Managed or Do it Yourself?
Trusted Advisor for IT & Telecommunications Sourcing
Managed SD-WAN: Efficiency meets control
Optimal network management for modern companies
Managed SD-WAN: Efficiency meets control
SD-WAN revolutionizes enterprise network management through software-defined control, centralized management and flexible provisioning. But success depends on the right operational strategy, whether self-managed, jointly managed or fully managed.
Advantages of a managed SD-WAN approach:
- Clear SLAs & central troubleshooting: Standardized processes and guaranteed performance across all locations
- Simple contract structure: Flexible expansion of capacities and regions without complex billing
- Integrated security: SASE and Zero Trust solutions for a secure, global network
- Virtual network architecture: Scalable cloud and edge connections without physical dependency
- Partnership approach: Support from experienced service providers for a smooth migration
The solution: SAVECALL helps you find the right SD-WAN operating strategy for your site connectivity, whether self-managed, co-managed or fully managed.
What this article covers: This article compares the SD-WAN operating models do-it-yourself, co-management and fully managed, focusing on SLAs, contract complexity and security. The key question: which SD-WAN operations strategy best fits your organization’s capabilities and goals?
Managed SD-WAN vs. do-it-yourself: the basic models
SD-WAN, a software-based approach to wide-area network management, provides the flexibility, agility, efficiency and improved usability that modern organizations require. It is characterized by simple deployment, centralized manageability and lower costs. The key benefit is the ability to manage multiple connection types, from broadband to LTE to MPLS, to enable a better application experience for the end user at each location. As organizations consider deployment architectures and potential partners, the question is whether to go the do-it-yourself route alone, opt for a jointly managed service, or a fully managed service. It’s important to know exactly what each option entails before making a decision.
Do-it-yourself model: Some organizations purchase SD-WAN routing equipment and install and configure it themselves at each site. Others hire a system integrator to take these steps and then manage the network themselves. Or they hire a managed network services provider that offers different variations, from provisioning and maintenance to co-managed or fully managed network services.
Co-management mode: Many organizations find that scaling an SD-WAN to global sites can become very complex and they need a managed service provider. In co-management mode, the service provider ensures deployment and management of the infrastructure while internal teams create new application-based routing policies via a web portal and change them instantly as required. Other organizations need more comprehensive support so internal teams can focus on more strategic areas of cloud transformation. A managed service provider helps select the right mix of broadband, 4G/LTE transport and MPLS. Which model fits best depends on the organization’s capabilities and priorities.
Three reasons for a managed SD-WAN service
SLAs and problem-solving processes: With the do-it-yourself model, SLAs must be agreed with each ISP individually worldwide and can be difficult to enforce and harmonize, as each provider handles technical support, communication and dispute resolution differently. A managed service, by contrast, applies uniform SLAs for performance and connectivity across all locations, with a single point of contact for technical support, troubleshooting and communication across all ISPs.
Contractual complexity: With the do-it-yourself model, numerous contracts and invoices have to be controlled and managed globally, which is complex and time-consuming. A managed service, on the other hand, brings simpler billing and greater commercial flexibility, with the ability to add new regions, capacity or security services as needed, or flexibly terminate sites using sunset clauses.
Security: SD-WAN offers native support for IPSec tunneling to encrypt traffic, but this alone is not a panacea, additional protection measures such as SASE or Zero Trust are required. With a managed service, connectivity becomes an integral part of security: organizations can choose from additional services such as cloud-based web traffic filtering, role-based access controls and internal network segmentation.
From physical to virtual
With SD-WAN, devices are installed at each location that orchestrate data traffic via an overlay network. Smaller companies often opt for a dedicated SD-WAN appliance. For companies with more demanding network requirements, these appliances can be automatically connected to cloud or network-based platforms that support virtualized functions such as firewalls, routers and application optimization at scale and speed.
How SAVECALL supports your operating model choice
That’s why SAVECALL works with partners who can provide any type of SD-WAN, so we can support our customers in their development and transition to SD-WAN, whichever way they choose to go.
Conclusion
There is no single way to manage SD-WAN. Organizations need to carefully determine which path is best for them, taking into account their business requirements over the next two to five years. We look forward to your questions.

Written by
Frank Frommknecht
Key Account Consultant, SAVECALL
Has supported companies for more than 20 years in selecting and optimising their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and finding the right solution strategically.
Sources
- SAVECALL: Managed SD-WAN service provider guide, savecall.de/en/managed-sd-wan-service-provider
- SAVECALL: Enterprise IT security, SASE, XDR & cloud, savecall.de/en/security
- SAVECALL: Enterprise WAN, SD-WAN, MPLS & Ethernet, savecall.de/en/wan
Frequently asked questions
Frequently asked questions about Managed SD-WAN
In the do-it-yourself model, a company purchases SD-WAN routing equipment and installs and configures it themselves at each site. Alternatively, a system integrator is hired for installation while the network is then managed internally. This model requires in-house expertise and capacity but offers the greatest control over implementation.
In co-management mode, the service provider ensures deployment and management of the infrastructure while internal teams create new application-based routing policies themselves via a web portal. With a fully managed service, the provider also takes over these strategic tasks, letting internal teams focus entirely on cloud transformation and end-user experience.
SLAs must be agreed with each ISP individually worldwide and can be difficult to enforce and harmonize, since each provider handles technical support, communication and dispute resolution differently. A managed service instead offers uniform SLAs and a single point of contact for technical support across all ISPs.
In the do-it-yourself model, numerous contracts and invoices have to be controlled and managed globally, which is complex and time-consuming. A managed service instead brings simpler billing and greater commercial flexibility, for example to add new regions or capacity as needed.
SD-WAN offers native support for IPSec tunneling to encrypt traffic, but this alone is not a panacea. Additional protection measures such as SASE or Zero Trust are required to cover web traffic filtering, role-based access controls and network segmentation.
SAVECALL works with partners who can provide any type of SD-WAN, whether do-it-yourself, co-managed or fully managed. This way SAVECALL supports companies in developing and transitioning to SD-WAN, tailored to their capabilities, priorities and business requirements over the coming years.
Articles that may also interest you
Why
Telecom & IT sourcing. Worldwide. Carrier-independent.
Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.
- 80+ carriers worldwide
- One point of contact
- One SLA
- One portal: mySAVECALL
- Min. 20% savings



