Home/Solutions/Hybrid SD-WAN Platform
SD-WAN · Multi-Link Bonding · LEO Integration · Hybrid WAN

Hybrid SD-WAN
Platform

End-to-end SD-WAN and transport-layer orchestration unifying LEO satellite, 4G/5G cellular, fiber, and microwave into a single deterministic IP fabric — with real-time telemetry, application-aware QoS, and sub-300ms failover. Fiber-class reliability anywhere on the planet.

Multi-GbpsAggregate Throughput
<300 msLink Failover Time
>95%Link Utilization Efficiency
L7Application-Aware QoS
AES-256All-Tunnel Encryption
Multi-Link Bonding·LEO + 5G + Fiber + Microwave·Sub-300ms Failover·Application-Aware QoS L7·Adaptive FEC·Zero-Touch Provisioning·AES-256 All Tunnels·VRF Segmentation·NetFlow / IPFIX Telemetry·Starlink Integration· Multi-Link Bonding·LEO + 5G + Fiber + Microwave·Sub-300ms Failover·Application-Aware QoS L7·Adaptive FEC·Zero-Touch Provisioning·
Platform Architecture

The CLATA Hybrid Transport Framework

The CLATA Hybrid Network Platform is an enterprise-grade SD-WAN and transport orchestration framework built on a Layer-3 overlay fabric with dynamic routing intelligence. It unifies heterogeneous WAN links — LEO satellite, 4G/5G cellular, fiber broadband, and licensed microwave — into a single managed IP transport with deterministic performance guarantees.

Each edge node (CPE, vessel gateway, vehicle aggregation unit, or vCPE) establishes encrypted DMVPN/IPsec tunnels over all active uplinks simultaneously. The centralized controller layer monitors real-time link telemetry every 500 ms and computes optimal per-application forwarding paths based on SLA thresholds for latency, jitter, packet loss, and throughput.

Performance is equal to carrier-grade MPLS while maintaining full flexibility for deployment in fixed enterprise sites, remote field operations, mobile maritime platforms, and cloud-native virtual environments.

Supported WAN Interface Types

LEO Satellite GEO Satellite (VSAT) 4G LTE 5G NR Fiber / Ethernet Licensed Microwave ADSL / Cable MPLS
CLATA HYBRID PLATFORM — REFERENCE ARCHITECTURE
┌─────────────────────────────────────┐
│         CLOUD CONTROLLER            │
│  Policy Engine · Telemetry · NOC    │
│  ZTP · Analytics · SLA Reporting    │
└───────┬─────────────┬───────────────┘
        │ Encrypted   │ Encrypted
        │ Control     │ Control
        ▼             ▼
┌───────────┐   ┌───────────────────┐
│  HUB EDGE │   │  REMOTE EDGE CPE  │
│  (DC/NOC) │   │ (Site/Vessel/Veh.)│
└─────┬─────┘   └──┬──┬──┬──┬──────┘
      │             │  │  │  │
    MPLS/           │  │  │  └─ 🛰️ LEO Satellite
    Fiber           │  │  └──── 📱 4G / 5G LTE
                    │  └─────── 🗼 Microwave PTP
                    └────────── 🌐 Fiber/ADSL

MULTI-LINK ENGINE:
├── Real-time bonding (active-active)
├── Adaptive FEC (packet loss recovery)
├── Per-flow path selection (SLA-based)
└── Session persistence (failover safe)

QoS POLICY ENGINE (L7):
├── Voice/Video  → Priority Queue (EF)
├── SCADA/IoT    → Guaranteed BW (AF41)
├── Business     → Normal (AF21)
└── Best Effort  → Default Queue (BE)
          
Core Capabilities

Technical Feature Set

🔄

Real-Time Multi-Link Bonding

Active-active aggregation of heterogeneous WAN interfaces at the IP layer. Adaptive packet distribution algorithms compensate for latency variance between links (e.g., fiber + LEO satellite).

  • Aggregate throughput: scalable to multi-Gbps per node
  • Link utilization efficiency: >95% with mixed-latency uplinks
  • Per-packet or per-flow steering with ECMP
  • WAN link health monitored every 500 ms

Sub-300ms Seamless Failover

Dynamic path selection based on configurable SLA thresholds (<80 ms RTT, <0.5% packet loss). Automatic rerouting is completed in under 300 ms — no session drops, no VoIP call interruption.

  • Typical switchover: <300 ms measured end-to-end
  • Session persistence via continuous tunnel state sync
  • TCP optimization prevents spurious retransmits during failover
  • Configurable SLA thresholds per application class
🛡️

Adaptive FEC — Packet Loss Recovery

Forward Error Correction implemented at the session level to mitigate satellite-induced packet loss (LEO orbital mechanics, weather events) and improve effective TCP throughput on degraded links.

  • Dynamically applied only when packet loss > threshold
  • Overhead controlled: typically 5–20% depending on loss rate
  • Significant improvement on LEO links during adverse conditions
  • Compatible with all transport protocols (TCP, UDP, QUIC)
📊

Application-Aware QoS — Layer 7

Deep Packet Inspection classifies traffic at Layer 7. Voice, video conferencing, SCADA, and telemetry receive dedicated priority queuing and guaranteed bandwidth — ensuring mission-critical traffic is never starved by bulk transfers.

  • L7 DPI with 3,000+ application signatures
  • Per-application bandwidth guarantee and priority queue
  • Hierarchical policies: global → site-type → application
  • Dynamic policy update without traffic disruption
🤖

Zero-Touch Provisioning (ZTP)

Edge nodes auto-register with the controller using secure TLS 1.3 token exchange. Configuration, policy, and firmware are pushed from the central controller — no on-site technical expertise required for deployment.

  • TLS 1.3 secure device bootstrapping
  • Certificate-based device identity and authentication
  • Configuration templates per site-type or customer profile
  • Firmware upgrade orchestration via controller
🔒

Security & Network Segmentation

AES-256 + SHA-2 encryption on all tunnels. VRF-based segmentation isolates management, production, and guest networks at the routing layer. Optional DPI-based intrusion detection and SIEM integration.

  • AES-256-GCM + SHA-256/384 HMAC on all tunnels
  • Per-zone VRF isolation (management / ops / guest)
  • Dynamic key rotation — configurable interval
  • SIEM integration via RESTful API and syslog export
LEO Satellite Integration

Optimized for Low Earth Orbit Networks

LEO satellite constellations (including Starlink) introduce unique transport challenges that standard SD-WAN platforms are not designed to handle: variable latency (20–80 ms orbital oscillation), elevated jitter, and periodic coverage gaps during handover between orbital planes. CLATA's platform includes a purpose-built LEO optimization layer that compensates for these characteristics.

🛰️ LEO Latency Compensation

The platform applies TCP acceleration and window scaling optimized for 20–80 ms RTT variance. Latency-sensitive applications (VoIP, video) are routed to terrestrial paths when available; LEO handles bulk and best-effort traffic.

📦 Adaptive MTU Management

Dynamically adjusts MTU to account for encapsulation overhead on Starlink and multi-hop satellite links, maintaining efficient TCP window utilization and preventing fragmentation-induced performance degradation.

🌦️ Weather-Aware Rerouting

Integrated signal quality telemetry from satellite terminals (RSSI, SNR, throughput) triggers proactive rerouting to terrestrial backup links when rain fade or beam handover degradation is detected — before packet loss begins.

🔀 Multi-Orbit Orchestration

Simultaneous LEO + GEO + terrestrial operation. Routing decisions based entirely on real-time per-link telemetry, not static metrics — the controller selects the best path for each application class at every measurement interval.

LEO Link Performance Profile
Typical Downlink100 – 300 Mbps
Typical Uplink20 – 60 Mbps
Latency Range20 – 80 ms RTT
Jitter (typical)5 – 20 ms
Packet Loss (clear)<0.1%
Orbital Altitude~550 km LEO
CoverageGlobal (most regions)
⚡ With CLATA's multi-link bonding, LEO satellite is combined with terrestrial links to achieve <30 ms effective latency for latency-sensitive applications via intelligent traffic steering.
Supported Deployment Topologies
Hub-and-Spoke: Branch/remote sites tunnel to HQ or cloud hub over LEO+LTE. Ideal for enterprise WAN and government field offices.
Full Mesh: Sites exchange traffic directly via distributed control plane. Used for embassy networks and multi-site operations centers.
Mobile Edge: Vessel or vehicle aggregation unit bonds LEO + cellular with seamless handoff between satellite coverage zones and port 4G/5G networks.
Cloud Gateway (vCPE): Virtualized controller and gateway deployed in customer cloud environment (AWS/Azure/GCP) or private data center.
Technical Specifications

Platform Performance Parameters

ParameterSpecificationNotes
MULTI-LINK TRANSPORT ENGINE
Aggregate ThroughputScalable to multi-Gbps per nodeLimited by sum of active WAN link capacity
Max WAN InterfacesUp to 8 per edge nodeAny mix: LEO, 4G/5G, fiber, microwave, VSAT
Bonding ModeActive-Active (simultaneous use)Adaptive per-packet or per-flow distribution
Link Utilization>95%Across mixed-latency links including LEO
Telemetry Interval500 ms per linkRTT, jitter, loss, throughput, RSSI
FAILOVER & REDUNDANCY
Failover Detection<1 secondContinuous probe-based monitoring
Failover Completion<300 ms (typical)End-to-end including reroute convergence
Session PersistenceFull (no session drops)TCP state sync across active tunnels
SLA Trigger ThresholdsConfigurable per app-classDefault: RTT >80ms, Loss >0.5%, Jitter >30ms
SECURITY
Tunnel EncryptionAES-256-GCMAll WAN tunnels — no unencrypted traffic
AuthenticationSHA-256 / SHA-384 HMACPer-packet integrity verification
Key ManagementDynamic rotation (configurable)Automated revocation via controller
Network SegmentationVRF per zoneManagement / Production / Guest / IoT
Optional DPIL7 IDS/IPS moduleSIEM integration via REST API / syslog
QoS & TRAFFIC MANAGEMENT
Classification DepthLayer 7 DPI3,000+ application signatures
Queue TypesPriority, WFQ, CBWFQ, WREDPer-application policy
Marking / DSCPFull DSCP remarkingEF, AF41, AF21, CS1 standard classes
FECAdaptive — triggered by loss thresholdTypical overhead: 5–20%
DEPLOYMENT & MANAGEMENT
ProvisioningZero-Touch (TLS 1.3)Auto-register → pull config → activate
ControllerCloud or On-PremisePrivate cloud deployment available
Monitoring APIRESTful API + NETCONF + SNMPNMS and NOC integration
Telemetry ExportNetFlow v9 / IPFIX / sFlow5-second granularity per edge
ReportingSLA compliance, uptime, jitter heatmapsJSON/CSV export, white-label dashboards
Use Cases

SD-WAN in Action

Enterprise / Government
Hybrid Branch WAN — Embassy Network
A foreign ministry connects 45 embassies worldwide. Each embassy has a LEO satellite primary link plus a local ISP secondary. The SD-WAN controller enforces end-to-end AES-256 encryption, VRF-isolates classified traffic, and provides unified NOC visibility from headquarters — regardless of underlying transport.
45Embassy sites
AES-256All links
UnifiedNOC view
Maritime
Vessel Multi-Link Broadband
50 cargo vessels on Atlantic routes. Each vessel bonds LEO satellite (200 Mbps primary) with coastal 4G/LTE (secondary). SD-WAN QoS prioritizes bridge navigation comms and VSAT AIS over passenger Wi-Fi. Seamless handoff at port entry from satellite to terrestrial 5G — zero session drops.
50Vessels
200MbpsLEO primary
<300msHandoff time
Mining / Industrial
Off-Grid Site WAN — Africa
A mining operation 300 km from city infrastructure bonds LEO satellite + private LTE into a single managed fabric. SCADA traffic gets guaranteed 2 Mbps low-latency path on the LTE link; HD video surveillance and crew internet share the LEO uplink. Solar-powered edge nodes with 72h battery backup.
<5msSCADA latency
72hBattery backup
SolarZero grid

Design Your Hybrid WAN Architecture

Our SD-WAN architects will model your topology, define SLA thresholds, and recommend the optimal multi-link configuration for your sites, applications, and budget.

SD-WAN — Africa & Remote Deployments

Enterprise SD-WAN with Starlink Bonding

CLATA delivers multi-WAN SD-WAN bonding proven across remote BTS sites in East Africa. Starlink + cellular bonded into one resilient WAN delivers 200–360 Mbps with zero packet loss — replacing VSAT at a fraction of the cost.

Multi-WAN Bonding — Proven Results

  • 3× Starlink + Multi-WAN router at BTS sites
  • 200–360 Mbps aggregate downlink
  • 40–130 Mbps aggregate uplink
  • Zero packet loss via WAN Smoothing + FEC
  • Deployed across 67+ remote African sites
  • LTE data offload for mobile operators
🌍

Africa & Global SD-WAN

  • Uganda, Kenya, Sudan, Congo DRC, Mauritius
  • Zero-touch cloud provisioning
  • AWS cloud hub integration
  • 24/7 NOC monitoring included
  • Endpoint security + NGFW layer
  • 35+ countries served globally
Get SD-WAN Quote →