The orchestration plane is a new central function that traditional networks do not have. In Catalyst SD-WAN, the control plane and management plane are separated from edge devices and rely on centralized controllers (the Manager - vManage and the Controller - vSmart). Because of that, two major challenges emerge:
- Security becomes critical. What if an attacker compromises the centralized controllers? They could bring down the whole overlay fabric. - What if a rogue device joins the overlay fabric? It could eavesdrop on business-critical traffic.
- Automation becomes mandatory. How would edge routers discover controllers in an automated way without needing manual configuration? The solution will not scale if network administrators have to manually configure controller IP addresses on every router.
To account for these new major requirements, Cisco Catalyst SD-WAN has introduced the orchestration plane.