Mode: With private WAN routers¶
Warning
Private WAN routers will be deprecated in SD-WAN on August 1, 2025. Please see Migrating to managed mesh for information on migrating an existing deployment using private WAN routers to a managed mesh.
Note
The With private WAN routers mode was the only type of private WAN available prior to version 6.5. It requires provisioning private WAN router nodes.
In the example environment below, showing bonds in a single private WAN space using private WAN routers, a host on the 10.1.0.0/24 network can communicate with a host on the 10.6.0.0/24 network, no matter which aggregator or routing group either bond is assigned to.

Space traffic between aggregators and PWAN routers is tunneled over an encrypted GRE connection—one tunnel for each space.
Space traffic between PWAN routers in different routing groups is tunneled over an encrypted GRE connection—one tunnel for each space, in a full mesh between all PWAN routers.
Bonds with a mix of PWAN-included and PWAN-excluded connected IPs route their traffic as shown in this diagram:
