NEW BLOG
Cisco Live 2026: How Cisco Assurance is Turning AgenticOps into Trusted Outcomes

Industry

Assuring Your SD-WAN Deployment With Cisco ThousandEyes

By Al da Silva
| | 10 min read

Summary

SD-WAN and SASE deliver secure, flexible connectivity, but their overlay tunnels hide the underlay networks traffic traverses—leaving operators blind when performance degrades in networks they don't own. Cisco ThousandEyes closes this gap by correlating overlay, underlay, and application performance in a single view, giving teams a vendor-neutral way to pinpoint issues and restore service fast.


It's 9 AM on the busiest trading day of the quarter. Users at a dozen sites can't reach the payments platform, the service desk queue is climbing, and every dashboard you own is green. The SD-WAN fabric reports all the tunnels are healthy. The Secure Access Service Edge (SASE) portal shows no incidents. Yet the business is bleeding. If you operate an SD-WAN or SASE environment, chances are you've lived some version of this morning, and the reason is almost always the same: the problem lives in a part of the network you can't see.

SD-WAN earned its dominance for good reason: ubiquitous connectivity over any IP transport, whether MPLS, public Internet or 4G/5G, all under a controller-based architecture with policy-driven control of exactly how data plane traffic is routed. That control is what enables Direct Internet Access (DIA), where instead of hauling Internet-bound traffic from a remote site back to a central circuit at the data center, you break it out locally. The trade-off is that DIA can bypass traditional perimeter security. Most SD-WAN routers embed protections such as zone-based firewalling, deep packet inspection, and proxying, but managing that security policy across hundreds or thousands of devices becomes operationally burdensome, even with central management.

This is where SASE comes in. SASE converges SD-WAN with cloud-delivered security, providing a single place to administer and enforce security policies. Just as within the SD-WAN fabric, routers establish secure tunnels (typically IPsec) to the cloud security infrastructure for Internet-bound traffic. So, wherever traffic is destined, whether data center or Internet, it gets there inside a secure tunnel.

Overlay connectivity from remote sites to Data Centers and Cloud Delivered Security.
Figure 1: Overlay connectivity from remote sites to Data Centers and Cloud Delivered Security.

Think of a retailer's point-of-sale (POS) terminals, a bank's loan and investment platforms, or a hospital's telehealth services. Whatever the industry, the business now runs across the SD-WAN fabric and SASE connectivity. So, when things go wrong—and they inevitably do—restoring service fast is priority number one. Which raises the uncomfortable question: how do you assure a business-critical environment when you can’t see the end-to-end delivery chain?

The Overlay vs Underlay Dilemma

ThousandEyes has helped organizations globally to pinpoint the causes of bad user experience by correlating application performance with network metrics over time. With SD-WAN and SASE, a new dimension to networking is introduced. The secure network tunnels used to provide simplified connectivity across untrusted networks create a co-dependent network duality: the overlay and underlay networks.

The overlay network is defined by the secure tunnels created between sites and to cloud delivered security services. These tunnels create a point-to-point connection between two separate locations from a user traffic perspective. Whenever a user wants to access a resource in the data center, for example, that users' data is encapsulated in a secure tunnel and transported between the remote site and the data center.

These tunnels are established over a routed network (Internet, MPLS, 4G/5G, etc.) that provides the reachability between the two sites connected at either end of the tunnel. This is known as the underlay network. Without the underlay, the overlay tunnels simply can't exist. And the underlay is rarely simple, as it can span a large, complex mesh of routers and interconnected providers, such as the Internet itself. Critically, most of that underlay belongs to someone else. When performance degrades in a provider's network you can't see into, you can't prove it, escalate it, or fix it, and the user experience suffers all the same.

Diagram highlighting how underlay WAN circuits rely on many interconnected routers facilitating overlay tunnel establishment
Figure 2: Reality of the underlay supporting overlay connectivity.

The primary challenge is that overlay and underlay visibility is often disjointed. User traffic carried in the overlay has no notion of the underlay it is being carried on. Therefore, traditional tools like traceroute, when run over the overlay, will “see” the entire underlay as just a single hop between the two tunnel endpoints, when, in reality, it may traverse dozens of routed hops across multiple providers.

Platform-native monitoring helps, but it sees the world from inside the vendor's own fabric: tunnel health, edge status, and PoP performance. It can't see hop-by-hop into an underlay the vendor doesn't own, and it rarely follows the application path beyond the vendor's edge. Operators are forced to manually reconcile data across disparate platforms, dashboards and tools, struggling to correlate cause and effect across the underlay, overlay, and application layers.

SD-WAN Assurance Using ThousandEyes

ThousandEyes addresses the overlay/underlay disconnect through the synthetic testing of both the application (and the overlay path it takes) and the underlay tunnel termination points. A single ThousandEyes agent, deployed where the users reside, runs synthetic tests at regular intervals. Some target the application over the overlay, while others target the underlay tunnel termination points. Overlay testing typically requires no special handling: the synthetic traffic follows the same path, and is subject to the same policies, as a real user's traffic. Because the tests run around the clock, you're not just troubleshooting after the fact; you have a performance baseline from before, during, and after any incident.

For underlay testing, the need to route the test traffic to an underlay path will vary, depending on the SD-WAN/SASE implementation. Irrespective of how it is achieved, the ThousandEyes platform will correlate the overlay metrics with the underlay metrics in a single view we call “Multi-Service Views.”

In simple terms, Multi-Service Views aggregates the metrics and path visualization of multiple tests into a single view. This allows customers to visualize both overlay and underlay paths together to quickly and easily pinpoint how underlay performance issues are impacting overlay user experiences. More importantly, ThousandEyes can identify where and in which networks performance degradation occurs, providing a vendor-neutral perspective on the entire delivery chain. Since ThousandEyes operates independently of the underlying transport providers, it provides an objective, third-party view of performance, allowing teams to hold service providers accountable based on data rather than assumptions.

ThousandEyes screenshot of path trace between the agent and both overlay & underlay destinations, highlighting root cause
Figure 3: Overlay and underlay visibility (multi-service views) highlighting how underlay impacts overlay experience and pinpointing the root cause of the problem.

Furthermore, for publicly routed overlay and underlay destinations, ThousandEyes collects BGP routing information, reporting on path changes and routing updates that may impact performance. Understanding BGP AS path data, and how it changes over time, lets organizations see which networks their traffic is transiting. That insight informs smarter routing and transport decisions, and just as importantly, provides a mechanism that helps your organization maintain its security, compliance, and data sovereignty requirements.

Understanding the root cause is critical in troubleshooting, and overlay/underlay networking makes it genuinely hard to isolate. The stakes are also rising. User experience is no longer just a network team concern: network managers are increasingly measured against employee satisfaction, and business leaders draw a straight line from digital experience to productivity. Secure connectivity isn't optional in a world of ever-increasing compromise, but security shouldn't cost you visibility. The answer is to assure the overlay and underlay together, with actionable insights that allow you to identify and remediate issues fast. As an independent platform, ThousandEyes bridges the visibility gap that overlay networking introduces, correlating the overlay, the underlay, and the application experience in a single view. So, the next time users are screaming and the dashboards are green, you'll know where to look. To see ThousandEyes SD-WAN and SASE assurance at work in your own environment, you can sign up to a free 15-Day trial today, or for a deeper discussion, contact your local account manager.

related blogs

Upgrade your browser to view our website properly.

Please download the latest version of Chrome, Firefox or Microsoft Edge.

More detail

Subscribe to the ThousandEyes Blog

Stay connected with blog updates and outage reports delivered while they're still fresh.