Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Sd Wan Engineer

  • 22 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Design, deploy, and operate SD-WAN: overlay WAN topologies, underlay diversity, application-aware routing, SASE/ZTNA insertion, orchestration templates, and brownfield migration.

About

Guides SD-WAN design, deployment, and operations covering overlay WAN topologies, underlay diversity, path selection, SASE integration, orchestration, and brownfield migration. A developer uses it when architecting application-aware WAN, branch connectivity, or migrating off legacy MPLS/VPN, vendor-agnostic across Viptela, VeloCloud, and Prisma SD-WAN.

  • Defines path selection, SLA classes, and application-aware routing policies
  • Covers SASE/ZTNA insertion, branch CPE roles, and brownfield migration

Sd Wan Engineer by the numbers

  • 22 all-time installs (skills.sh)
  • Ranked #808 of 1,039 Cloud & Infrastructure skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill sd-wan-engineer

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs22
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Design, deploy, and operate SD-WAN: overlay WAN topologies, underlay diversity, application-aware routing, SASE/ZTNA insertion, orchestration templates, and brownfield migration.

Files

SKILL.mdMarkdownGitHub ↗

SD-WAN (Software-Defined WAN) Engineer

When to Use

  • Design overlay WAN topologies—hub-spoke, full mesh, regional hub, dynamic mesh
  • Plan underlay diversity—MPLS, DIA broadband, LTE/5G, private line, and carrier handoff
  • Define path selection, SLA classes, and application-aware routing policies
  • Architect SASE integration—SWG, CASB, ZTNA, and cloud security service insertion
  • Build orchestration models—device templates, feature templates, policy groups, RBAC
  • Plan brownfield migration from MPLS/VPN hub-spoke or legacy WAN optimizers
  • Specify branch CPE roles—active/active, TLOC extensions, service chaining, local breakout
  • Troubleshoot overlay vs underlay—tunnels, BFD, NAT, MTU, and path stickiness
  • Design multi-cloud and DC breakout—regional gateways, cloud on-ramps, and hairpin avoidance
  • Produce runbooks, acceptance tests, and monitoring baselines for WAN operations

When NOT to Use

  • Carrier core BGP/MPLS design, IX peering, or internet backbone routing only → network-backbone-architect
  • Cloud landing zone, VPC design, and Well-Architected service selection → cloud-architect, enterprise-cloud-architect
  • Provision cloud subnets, VPN to cloud, and managed LB without SD-WAN overlay focus → cloud-engineer
  • Cloud IAM, CSPM, and org guardrails as primary deliverable → cloud-security-engineer
  • Corporate security program, IdP, and endpoint controls without WAN architecture → information-security-engineer
  • Terraform modules, CI/CD, and K8s delivery without SD-WAN design → infrastructure-engineer
  • SLO programs, on-call, and production incident process as main task → site-reliability-engineer
  • Application throughput, caching, and horizontal scale without WAN path design → high-concurrency-scalability
  • REST/GraphQL and enterprise application integration → enterprise-integration-api-developer
  • Physical rack, power, and cabling without SD-WAN edge role → infrastructure-engineer, field-services-engineer

Related skills

NeedSkill
Carrier backbone, BGP/MPLS core, DCI at scalenetwork-backbone-architect
Cloud reference architecture and hybrid connectivitycloud-architect
Enterprise cloud governance and multi-BU programsenterprise-cloud-architect
Implement cloud networking and managed connectivitycloud-engineer
Cloud network security controls and posturecloud-security-engineer
IaC, physical build, and platform deliveryinfrastructure-engineer
Reliability engineering, SLOs, and production incidentssite-reliability-engineer
Application-scale concurrency and load distributionhigh-concurrency-scalability
Corporate security program and toolinginformation-security-engineer

Core Workflows

1. Scope, constraints, and success criteria

Clarify sites, traffic matrix, compliance, and migration constraints.

See `references/sd_wan_engineer_scope.md`.

2. Overlay topology and underlay

Select hub roles, mesh policy, and circuit mix per site class.

See `references/overlay_topology_and_underlay.md`.

3. Path selection, SLA, and application routing

Define business policies, SLA classes, and app identification.

See `references/path_selection_sla_and_app_routing.md`.

4. Security, SASE, and service insertion

Place NGFW, SWG, ZTNA, and local vs centralized breakout.

See `references/security_sase_and_ztna_insertion.md`.

5. Orchestration, templates, and day-two operations

Model controllers, templates, change workflow, and observability.

See `references/orchestration_templates_and_operations.md`.

6. Migration, HA, and troubleshooting

Plan cutover waves, HA modes, and overlay/underlay fault isolation.

See `references/migration_ha_troubleshooting.md`.

Outputs

  • WAN context — site inventory, traffic matrix, critical apps, and compliance constraints
  • Logical topology — overlay roles, hub map, regional gateways, and breakout points
  • Underlay map — circuits per site, diversity, carrier handoff, and IP addressing plan
  • Policy catalog — SLA classes, path selection rules, and application definitions
  • Security architecture — service insertion, SASE integration, and segmentation zones
  • Orchestration model — template hierarchy, RBAC, and promotion workflow
  • Migration plan — waves, rollback triggers, parallel-run criteria, and acceptance tests
  • Operations pack — dashboards, alarms, runbooks, and escalation matrix

Principles

  • Treat underlay independence as a design goal—overlay must survive single-circuit loss where required
  • Prefer explicit SLA classes over opaque “best path” defaults; document stickiness and failover timers
  • Minimize hairpinning—local breakout for trusted SaaS and regional gateways for cloud on-ramps
  • Design brownfield with parallel run and measurable cutover gates, not big-bang unless constrained
  • Separate control plane (orchestrator) resilience from data plane (edge) HA in runbooks
  • Use vendor concepts generically; validate against target platform docs before production config

Related skills

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.