KasperskyNetwork Security

    SD-WAN

    A fault-tolerant SD-WAN that becomes the on-ramp to SASE.

    Kaspersky SD-WAN builds fault-tolerant, secure networks with unified management for distributed businesses — protecting continuity and enhancing productivity across branches. It connects locations over any channel (MPLS, Ethernet, LTE) with Zero Touch Provisioning, and its Virtual Network Functions manager lets you deploy Kaspersky and third-party security tools on top, making it an essential first step toward SASE. Faltrox deploys and manages the fabric.

    Overview

    What SD-WAN is

    Secure Access Service Edge (SASE) is the synergy of network and security services — agile, reliable networks with unified security delivered from the cloud, protecting the whole company network regardless of where users are. Kaspersky SD-WAN is the network foundation that makes building SASE practical: a reliable distributed network you can layer integrated security onto.

    It uses any available communication channel — MPLS VPN, Ethernet, 4G/LTE, or a combination — to connect new locations, with Zero Touch Provisioning that brings branches online without on-site configuration. Centralised orchestration manages a network of any size through one web interface or API, link management enforces SLAs for business-critical apps, and the VNF manager deploys Kaspersky and third-party security functions as virtual services. Built-in DPI, stateful firewall, and high-speed encryption secure the fabric itself. Faltrox operates it end to end.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Distributed Branches

    Connects branch offices to the corporate network over any channel with fault-tolerant tunnels.

    02

    Any Communication Channel

    MPLS VPN, Ethernet, PPPoE, and 4G/LTE — or any combination — for flexible connectivity.

    03

    Business-Critical Apps

    Application-aware routing and per-app SLAs keep critical application performance predictable.

    04

    Fabric Security

    Built-in DPI, stateful firewall, and high-speed per-channel encryption secure the network itself.

    05

    Security Service Chains

    The VNF manager deploys Kaspersky and third-party security tools as virtual network functions.

    06

    The Path to SASE

    Provides the reliable distributed network to layer unified, cloud-delivered security onto.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Provision

      Zero Touch Provisioning connects branches to the corporate network without additional on-site configuration, saving staff time.

    2. 02

      Connect

      CPE at each branch sets up tunnels to fault-tolerant SD-WAN gateways over any available channel, in mesh or hub-and-spoke topologies.

    3. 03

      Route

      Built-in DPI and application-aware routing steer traffic by application SLA, with WAN load balancing and quality control.

    4. 04

      Secure

      Stateful firewall, high-speed encryption per channel, and virtual network functions protect the fabric and its traffic.

    5. 05

      Manage

      The SD-WAN orchestrator provides unified control and monitoring of a network of any size through one interface or API.

    Capabilities

    Key capabilities

    Zero Touch Provisioning

    Connects new branches to the network with no additional configuration, via DHCP, static, or URL auth with two-factor support.

    Centralised Orchestration

    The SD-WAN orchestrator manages controllers, service chains, resources, and licences from one graphical interface and API.

    Application-Aware Routing

    Built-in DPI routes traffic by application and enforces per-application SLAs for business-critical performance.

    Virtual Network Functions

    The VNF manager deploys and manages Kaspersky and third-party security tools as virtual services on the fabric.

    Built-In Security

    Stateful firewall, high-speed encryption configurable per channel, and DPI protect the network itself.

    Fault Tolerance

    High-availability clustering, active/active gateway redundancy, and CPE redundancy (VRRP) keep the network up.

    SD-Branch

    LAN segmentation, local services (DHCP), local internet access, and universal CPE support at the branch edge.

    SLA-Based Link Management

    Active traffic probes assess loss, jitter, and delay, with FEC, packet duplication, and multilayer QoS for link quality.

    Works with

    Part of the platform

    Kaspersky products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Kaspersky SD-WAN for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Is this a security product or a networking product?

    Both, deliberately. Kaspersky SD-WAN is a networking fabric with built-in security — DPI, stateful firewall, per-channel encryption — and a VNF manager that lets you deploy additional Kaspersky and third-party security functions on top. It is positioned as the first step to building SASE.

    02What is Zero Touch Provisioning?

    It connects a new branch to the corporate network without any on-site configuration — a technician plugs in the CPE and it provisions itself via DHCP, static, or URL auth with two-factor support. For distributed businesses that removes a major deployment cost.

    03What connectivity can it use?

    Any available channel — MPLS VPN, Ethernet, PPPoE, and 4G/LTE — or any combination, across full mesh, partial mesh, and hub-and-spoke topologies, with SLA-based link management to keep critical applications performing.

    04Can we run third-party security tools on it?

    Yes. The Virtual Network Functions manager deploys both Kaspersky and third-party vendors’ security tools as virtual services, with service-chain lifecycle management — so you are not locked into a single security stack on the fabric.

    05How does Faltrox deliver it?

    We design the topology, deploy the gateways and branch CPE, configure the security functions and SLAs, and operate the orchestrator — delivering a managed secure network rather than hardware you configure yourself.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us