Mode: With private WAN routers (pending deprecation)
====================================================

.. warning::

    Private WAN routers will be deprecated in SD-WAN on August 1, 2025.
    Please see `Migrating to managed mesh <../private-wan-managed-mesh/migrating.html>`__
    for information on migrating an existing deployment using private WAN
    routers to a managed mesh.

.. toctree::
    :glob:
    :maxdepth: 1

    *

.. note::

    The **With private WAN routers** mode was the only type of private WAN
    available prior to version 6.5. It requires `provisioning private WAN router
    <../../private-wan/private-wan-with-private-wan-routers/provisioning-routers.html>`__
    nodes.

In the example environment below, showing bonds in a single private WAN space
using private WAN routers, a host on the 10.1.0.0/24 network can
communicate with a host on the 10.6.0.0/24 network, no matter which
aggregator or routing group either bond is assigned to.

|image0|

Space traffic between aggregators and PWAN routers is tunneled over an
encrypted GRE connection—one tunnel for each space.

Space traffic between PWAN routers in different routing groups is
tunneled over an encrypted GRE connection—one tunnel for each space, in
a full mesh between all PWAN routers.

Bonds with a mix of PWAN-included and PWAN-excluded connected IPs route
their traffic as shown in this diagram:

|image1|

.. |image0| image:: /attachments/11667032/11667619.png
.. |image1| image:: /attachments/11667032/12320973.png
