Listing Thumbnail

    Cisco Catalyst 8000V SD-WAN & Router - PAYG - DNA Advantage

     Info
    Deployed on AWS
    Free Trial
    The DNA Advantage Package for Catalyst 8000V (C8000V) includes all DNA Advantage feature sets and delivers multi-gigabit performance for enterprise-class networking services & VPN in the AWS cloud, as well as twice the IPSec throughput with IMIX packets.
    4.2

    Overview

    As part of Cisco's Cloud connect portfolio, the DNA Advantage package for Catalyst 8000V (C8000V) delivers the maximum performance available in AWS cloud for virtual networking services. Deliver high-speed secure VPN services with High Availability, strong Firewall protection, Application Visibility & Control, and more... This AMI runs Cisco IOS XE technology features and uses AWS instances with direct I/O path for higher & more consistent performance. The C8000V with full Cisco IOS-XE support enables customers to deploy the same enterprise-class networking services that they are so used to in their on-prem networks inside AWS. This AMI enables enterprise-class Routing, VPN, High-Availability, Firewall, IP SLA, VPC Interconnection, Application Visibility & Control, Performance Monitoring, Optimization. he familiar IOS XE CLI and RESTful API ensures easy deployment, monitoring, troubleshooting, and service orchestration.

    If you are using the Cisco Cloud Services Router 1000V (CSR 1000V) virtual router in autonomous mode, then you may want to use the GUI-driven migration tool to migrate those instances to Cisco Catalyst 8000V (C8000V) instance. This migration uses AWS CloudFormation template based automation to spin-up a new instance of Catalyst 8000V and copy the configuration files from the CSR 1000V instance. You can batch migrate up to ten CSR 1000V instances in one go. The migrated instances will include the enhanced "secure object storage" feature in C8000V that stores all sensitive configuration information in an encrypted file system inside the VM. See the http://cs.co/c8000v-aws-migration-tool  chapter in the Catalyst 8000V Configuration Guide for AWS for more details.

    Highlights

    • Enterprise-class VPN in AWS that's faster, cheaper, and more scalable than other VPN solutions. Manage both sides of your VPN for greater security. Familiar IOS-XE based VPN supports the same commands, tools, and logs as other Cisco Catalyst 8000 platforms.
    • More secure, reliable, and cost effective than native VPN. Feature-rich: IPSec, DMVPN, FlexVPN, GETVPN, EZVPN, SSL VPN, Zone-Based Firewall, and more...

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux Cisco IOS XE

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Cisco Catalyst 8000V SD-WAN & Router - PAYG - DNA Advantage

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (12)

     Info
    Dimension
    Cost/hour
    c5.large
    Recommended
    $2.34
    c5.9xlarge
    $4.12
    c5n.2xlarge
    $4.12
    t3.medium
    $2.34
    c5n.4xlarge
    $5.95
    c5n.large
    $3.29
    c5n.9xlarge
    $7.44
    c5n.xlarge
    $4.12
    c5.2xlarge
    $3.29
    c5.4xlarge
    $4.12

    AI Insights

     Info

    Dimensions summary

    You pay by the hour based on the AWS EC2 instance size you run this virtual router on. All twelve options bill on the same usage-based, hourly model with the DNA Advantage software license included. The dimensions are not feature tiers. Instead, each maps to a specific EC2 instance type, from smaller general-purpose sizes to larger compute and network-optimized ones. Your hourly rate rises as you select instances with more compute or network throughput. You choose the instance that matches your capacity needs, and you only pay while it runs.

    Top-of-mind questions for buyers

    Each dimension meters the running time of the virtual router software on a specific EC2 instance type, billed per hour. The DNA Advantage software license is included in that hourly rate. AWS bills the underlying EC2 compute separately on your AWS invoice.
    The hourly software charge applies only while the instance runs. When you stop the instance, the software metering stops and no software hours accrue. AWS may still charge for attached storage on a stopped instance, but that is separate from this software license.
    You select a new EC2 instance type when you deploy or resize. Billing follows whichever instance you run, so your hourly rate changes based on the instance you choose. The transition is not automatic; you decide when to switch to match your capacity needs.
    www.cisco.com
    Helpful?

    Vendor refund policy

    None

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    Complete the following steps to launch a Catalyst 8000V (C8000V) AMI: 1. Locate the C8000V product page by searching the AWS Marketplace for 'C8000V'. 2. On the C8000V product page, click the 'Continue' button. 3. Use either the 'Launch with EC2 Console' tab to complete the deployment of a C8000V AMI. Select the correct version and region, and click the 'Launch with EC2 Console' button. 4. The Launch Instances Wizard will open. Select the desired instance type and click 'Next'. 5. Select your desired VPC environment in the 'Network' pull-down menu. 6. Select your desired IP subnet for the first C8000V network interface in the 'Subnet' pull-down menu. 7. Add any additional network interfaces, and select the appropriate subnet for each to connect to. 8. Click 'Review and Launch', and then review the information for correctness. 9. If the information is correct, click 'Launch', and then either select an existing key pair to use for authentication, or create a new key pair. If you create a key pair, make sure to download and save the private key. 10. Click 'Launch Instances'. 11. From the AWS Console, wait for your instance to indicate a state of 'running'. It may take a few moments after that point, before you can connect to your C8000V instance. Connect to your instance using an SSH client, and the private SSH key selected or created earlier in these steps. Example: ssh -i mykeypair.pem ec2-user@myhostname.compute-1.amazonaws.com . 12. See notes for further instructions.

    Support

    Vendor support

    Cisco TAC support services for Pay As You Go is available for purchase through any Cisco Partner. Cisco Partner Locator: https://locatr.cloudapps.cisco.com/WWChannels/LOCATR/openBasicSearch.do . Support Community: https://supportforums.cisco.com/community/csr-amazon . A 30-day free trial period is included for first-time users. For questions or to obtain C8000V AMI access to the GovCloud region, contact ask-csr-aws-pm@cisco.com .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    50
    In Network Infrastructure
    Top
    50
    In Migration
    Top
    10
    In Network Infrastructure

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Virtual Private Network Protocols
    Support for IPSec, DMVPN, FlexVPN, GETVPN, EZVPN, and SSL VPN protocols for secure communications.
    Firewall and Security
    Zone-Based Firewall protection with Application Visibility and Control capabilities for traffic inspection and policy enforcement.
    High Availability and Redundancy
    High Availability configuration support with failover capabilities for enterprise-class networking services.
    Routing and Network Services
    Enterprise-class routing, IP SLA, VPC Interconnection, and performance monitoring and optimization capabilities.
    Management and API Support
    IOS XE CLI interface and RESTful API for deployment, monitoring, troubleshooting, and service orchestration.
    Next Generation Firewall Architecture
    High-performance firewall solution with core firewall, VPN, NAT, and advanced L4-L7 security services including application security, IPS, and anti-virus capabilities.
    Anti-Virus and Malware Protection
    Cloud-based anti-virus protection that detects and blocks spyware, adware, viruses, keyloggers, and other malware over POP3, HTTP, SMTP, and FTP protocols.
    Intrusion Detection and Prevention
    Intrusion detection and prevention (IPS) system integrated with application visibility and control through AppSecure for threat detection and workload protection.
    VPN and Secure Connectivity
    IPsec and full mesh VPN termination services enabling secure connectivity from on-premises data centers, campuses, and branches to AWS cloud across geographically dispersed VPCs.
    AWS Cloud Service Integration
    Native integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, Elastic Network Adapter support, and Gateway Load Balancer with L3 gateway and L4 load balancer capabilities.
    Application Layer Visibility and Control
    Complete application layer-7 visibility and control of traffic with next-generation firewall capabilities in AWS environments
    AI/ML-Powered Threat Detection
    AI/ML-powered inspection engine with researcher-grade signatures for detection of zero-day threats, exploits, malware, spyware, and command and control attacks
    Dynamic Policy Management
    Policy definitions that dynamically apply to cloud assets based on AWS tags, Application IDs, User IDs, geographies, or zones without manual intervention
    Cloud Infrastructure Integration
    Seamless integration with Gateway Load Balancer, AWS Auto Scaling, and Transit VPC with AWS Transit Gateway for protection across dynamic and large-scale deployments
    Advanced Threat Prevention Service
    Cloud-delivered Advanced Threat Prevention security service with market-leading threat coverage against known and zero-day threats while maintaining performance

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    29 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    48%
    42%
    10%
    0%
    0%
    6 AWS reviews
    |
    23 external reviews
    External reviews are from G2  and PeerSpot .
    PSaravanakumar

    Comprehensive visibility has improved branch monitoring and central management across our network

    Reviewed on Aug 28, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are a system integrator and a Cisco Select Partner, deploying all the Cisco portfolios like SD-WAN, switching, firewall, access point, and then Secure Access, our cybersecurity product. We have been a partner at Cisco for the last 8.5 years, dealing with Cisco Catalyst SD-WAN.

    What is most valuable?

    The features I find most valuable in Cisco Catalyst SD-WAN are based on our customer requirements, as the SD-WAN solution now has two solutions: Viptela-based SD-WAN and then Meraki-based SD-WAN. Cisco Catalyst SD-WAN has detailed features, and Meraki is a better solution, but compared to Cisco Catalyst SD-WAN, some features are not as detailed.

    From the visibility perspective, I find that we are able to monitor and manage the entire branch and user-level activities, providing better visibility. We can integrate with cloud-based solutions, such as Secure Access, and get all the information regarding who is accessing from branch to headquarters, source to destination, the servers, and all related data. We can monitor and manage who is accessing and what traffic is flowing, covering all the necessary aspects.

    What needs improvement?

    Cisco Catalyst SD-WAN can be improved in minimal ways, because they have updated it now, and the updated version is really good. The only concern is the cost; compared to others, the cost is higher, but the features are the same as a superior product, so we are expecting that cost. Some customers feel the cost is high, as not all users utilize all the features. They want some limited functionality, and we have two or three models of licenses only, where they need to buy either one license version or another. They are not using all the features, so they end up paying for everything.

    The pricing is the only concern regarding Cisco Catalyst SD-WAN; otherwise, all aspects are good.

    For how long have I used the solution?

    8.5 years

    Which other solutions did I evaluate?

    I see the competition to Cisco Catalyst SD-WAN mainly as the Palo Alto product, specifically the IRON product, which is the SD-WAN device similar to Cisco Catalyst SD-WAN. It features a centralized dashboard, management, large-scope deployment, and visibility, making them a competitor. Other products are available, but they are not at that much of a competitive level; Silver Peak is one example.

    What other advice do I have?

    Cisco does optimize the experience in a hybrid or distributed enterprise setup with the previous solution being Viptela Cisco Catalyst SD-WAN, which has now changed to Cisco Catalyst SD-WAN. We can now integrate Secure Access with Cisco Catalyst SD-WAN devices, allowing us to do all the policy optimization and distributed distribution functions.

    I think the operational efficiency of Cisco in my IT environment is a good aspect compared to Palo Alto, which is another competitor in enterprise-level solutions. Cisco Catalyst SD-WAN has some more features, enabling us to integrate with multiple platforms to monitor, manage, and adapt a single point of management. I would rate this solution a 9 out of 10.

    VENKATESHREDDY

    Reliable connectivity has improved operations while high costs and onboarding still need work

    Reviewed on Aug 27, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I am using Cisco Catalyst SD-WAN in my company and I recommend it to my customers as well.

    What is most valuable?

    The most valuable features of Cisco Catalyst SD-WAN include their support, which is really good compared to other vendors because we do deal with other vendors, and I have seen FortiGate. I don't think they will ever be able to match up to what Cisco Catalyst SD-WAN offerings are, that is for sure.

    Cisco Catalyst SD-WAN optimizes the experience in a hybrid or distributed enterprise setup, and it is good in enterprise setups as well. We have deployed it for our manufacturing customers and it is pretty stable.

    In terms of troubleshooting capabilities, end-to-end visibility affects my organization's ability to detect issues aggressively with their products, especially the software-defined networking stack for the LAN and WAN, where we have seen issues being detected much more aggressively, allowing us to resolve issues faster. Their AI features are really decent, so overall, it is a good solution.

    What needs improvement?

    Cisco Catalyst SD-WAN is good, but from a cost perspective, they need to think through and see how they can materialize and reduce costs, especially the hardware.

    Overall, I would rate Cisco Catalyst SD-WAN good, although they should start innovating more towards the AI landscape where we are seeing very high traction. At the SD-WAN level, they are fine, but they need to catch up, especially HPE post-acquisition of Juniper. When comparing Meraki versus Mist, Mist has better features, so those are some areas they need to catch up.

    To make Cisco Catalyst SD-WAN closer to a 10, I think cost is the first primary factor. The support and fundamental help assistance, especially during onboarding, could be much easier to enable small businesses to take it up.

    For how long have I used the solution?

    I have been working with Cisco Catalyst SD-WAN for three years.

    What do I think about the stability of the solution?

    The product is pretty stable.

    What do I think about the scalability of the solution?

    In terms of scalability, I would put Cisco Catalyst SD-WAN around eight on a scale of one to ten, as it scales well with the growing needs of my organization. We have used it in multiple diversified topologies and it has remained stable, being tested through time.

    From a scalability point of view, I don't see any concerns because we take into consideration their product-wise limitations when we are buying specific modules or things, so I think we are good over there.

    How are customer service and support?

    I would rate their technical support a ten.

    My impression of the end-to-end visibility offered by Cisco Catalyst SD-WAN depends on the channel partner who is providing the support, and their channel partners are pretty stable and quite good.

    How was the initial setup?

    The initial setup for Cisco Catalyst SD-WAN is very easy and pretty straightforward because their documentation is pretty detailed, so we haven't seen or run into issues.

    Which other solutions did I evaluate?

    I see HPE as good competition to Cisco Catalyst SD-WAN.

    HPE is cheaper.

    To make Cisco Catalyst SD-WAN closer to a 10, I think cost is the first primary factor. The support and fundamental help assistance, especially during onboarding, could be much easier to enable small businesses to take it up.

    What other advice do I have?

    Go ahead with your questions about Cisco products.

    Everything remains as is with these products. No changes.

    I purchased my Cisco products directly from Cisco.

    I would rate this review a 7 overall.

    Ashwani-Tyagi

    Centralized control has simplified cloud access and has improved operational visibility

    Reviewed on Aug 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Cisco Catalyst SD-WAN is for WAN connectivity only. When customers have a lot of workloads available on cloud and they need use cases like direct internet access, encryption, and better centralized control and centralized management of their complete WAN environment, those use cases generally fall under Cisco Catalyst SD-WAN.

    When customers are distributed across different locations, all the management, control and data plane are specific to those branches. From the management perspective, from the life cycle management or upgrade and update, we need to work on each and every branch. Once Cisco Catalyst SD-WAN is deployed, all of that can be done from a centralized location using the different management and control tools that Cisco has. Additionally, from the distributed perspective, if they want to access any application from the cloud, they would have to backhaul to their central data center and then access their applications on cloud. With Cisco Catalyst SD-WAN, direct internet access can be configured and they can reach out to the respective cloud locations directly. Zero-touch provisioning is something that can be implemented where you just create the formats and accordingly provision the new sites with zero-touch. You just bring the device and it will be automatically configured from the centralized management tools. There are multiple such features where Cisco Catalyst SD-WAN solves problems for customers.

    What is most valuable?

    One valuable feature is the scale at which it can be deployed for big enterprises. The application-aware routing they provide is another important feature. They have over 4,000 signatures of applications where the system can identify those applications and accordingly create the profile so that those applications can be given the best possible route depending on their requirement.

    Since we have a centralized control and a centralized management plane, for a distributed organization that has a lot of different offices, we can have complete visibility from a single point of connect. Accordingly, we can do the provisioning and configuration everything from a central place. This is a very useful architecture for an organization that is distributed or has multiple offices across different geographies.

    Having complete visibility into the complete Cisco Catalyst SD-WAN fabric helps not only to troubleshoot but also from a traffic engineering or capacity planning perspective or to ensure that proper uptime is maintained because we can proactively sense the issues in the network. This could be related to any malfunctioning at the product layer or it could be related to the sizing.

    All of those things actually add to the operational efficiency where we have vManage, vController, and all these tools to have centralized management, zero-touch provisioning enabled for the complete fabric. This actually gives real-time telematics of all devices. We can have complete visibility into the network on a real-time basis. That way we can ensure that we have better uptime for the overall Cisco Catalyst SD-WAN fabric.

    What needs improvement?

    If they can have better firewall features as their competitors have, such as Fortinet and Versa, that would help to place this solution better so that we can address security related things. If they can have all the IPS, IDS, everything built on all the edge devices, whether physical or virtual, that could be one improvement.

    Actually, if customers are existing Cisco customers, if Cisco can be more flexible to leverage the existing investment, that could be another important aspect to save on cost and be more competitive from a pricing perspective. Overall, the pricing or the segment that Cisco deals with is a bit premium, which they charge a bit premium against the competition on the licensing, hardware, and services.

    The implementation is not straightforward. You need a specialized partner or specialized people who can implement this. It can be simplified a bit from that perspective as well.

    Mostly the way we implement the policies for a big environment requires a lot of things that we need to take care of. If that can somehow be improved, because they have different components, like they have vManage, they have vSmart, and vBond and all these components have to work with a certain flow that they need to follow.

    For how long have I used the solution?

    I have been using this solution for around 8 or 9 years now.

    What do I think about the stability of the solution?

    Once it is set up, as I mentioned there are certain complexities in the initial configuration, but once it is customized or commissioned properly, then it is very smooth. We have a lot of visibility into the fabric and it performs well. For example, with zero-touch provisioning, if we are adding new sites, we can do it with a few simple clicks. That way it is very flexible.

    What do I think about the scalability of the solution?

    I think recently they have changed their licensing which was earlier on a per device bandwidth basis. Now licensing has gone in the new routing direction. Otherwise, it was a problem where we had to define the bandwidth for every router. I think it is one of the most costly solutions in this segment when we compete it with players like Fortinet. The cost is at the higher side.

    Cisco is more advanced since they have more granular based insights of the network. They have a dedicated controller unlike Fortinet where they have the control plan mostly built with the edge devices. That way we have a more granular way to implement the policies than Fortinet. If we are dealing with a very big network, then Cisco has an advantage of managing the big networks.

    How are customer service and support?

    Cisco TAC is one of the best. They are technically qualified and responsive.

    What was our ROI?

    There are many scenarios where we replace MPLS with the internet because now we have the flexibility to migrate to Cisco Catalyst SD-WAN and we do not need private connectivity such as MPLS. This cost optimization on the circuit is one part where we can leverage on all the available bandwidth unlike in MPLS or the traditional way where we have one active link and one passive. Here we can leverage on all the available transport and we can leverage on any type of connectivity because it is transparent to the transport that we are using, whether it is 5G, LTE, MPLS or whatever. Since it has centralized management from the operations perspective, it certainly adds value because now we can manage things from a centralized point. Earlier we were taking days to upgrade and update the edge devices, but from the centralized vManage or vControl, we can do it in a few hours. That way we can capture all these ROIs and can create a matrix and then share or present it to our customers.

    What other advice do I have?

    All their network products include LAN, WAN, Cisco Catalyst SD-WAN, and firewalls. As a Gold Partner, mostly the controller part is on cloud in most cases, while the edge device is on-premises. We sometimes purchase virtual firewall and virtual router to extend Cisco Catalyst SD-WAN fabric to these hyper-scalers. I would rate this solution an 8 out of 10.

    Vishnu Jadhav

    Centralized monitoring has improved branch connectivity and reduced troubleshooting time

    Reviewed on Jul 17, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Cisco Catalyst SD-WAN is managing and monitoring SD-WAN connectivity across branch locations. I primarily use it to monitor network health, troubleshoot tunnel and routing issues, configure policies, and ensure stable connectivity between branches and the data center. It also helps me quickly identify network problems, reduce downtime, and maintain secure, reliable application performance. In my day-to-day role, it plays an important part in incident management, network monitoring, and troubleshooting.

    One example from my daily work is when a branch office reported an intermittent connectivity issue. Using Cisco Catalyst SD-WAN, I checked the tunnel status, link health, and reviewed routing information from the central dashboard. This helped identify that one WAN link was unstable. After coordinating with the ISP and verifying the link was good, the branch connectivity was restored with minimal downtime. The centralized visibility and troubleshooting feature made it much faster to identify the issue and resolve it.

    How has it helped my organization?

    Cisco Catalyst SD-WAN is a valuable solution for my organization. It provides centralized management, good visibility, and helps us to reduce issue resolution time and improve network reliability.

    Cisco Catalyst SD-WAN has had a positive impact on my organization by improving network reliability and simplifying branch connectivity management. The centralized dashboard provides better visibility into the network, allowing us to identify and resolve issues more quickly. It has reduced troubleshooting time, improved application performance through intelligent path selection, and minimized downtime. Overall, it has increased operational efficiency and helped my IT team to manage the SD-WAN environment more efficiently.

    Since implementing Cisco Catalyst SD-WAN, we have seen faster troubleshooting and improved network visibility. The centralized dashboard allows us to identify connectivity issues much more quickly, reducing the time needed to diagnose and resolve incidents. We have also experienced fewer service disruptions because traffic failover maintains connectivity when WAN links have a problem. Overall, it has improved operational efficiency, reduced downtime, and enabled my team to manage the network more efficiently.

    What is most valuable?

    The features I find most valuable in Cisco Catalyst SD-WAN are centralized management, real-time monitoring, and policy-based automation. The centralized dashboard gives me a clear view of all branch sites, making it easy to manage and monitor tunnel health, bandwidth usage, and device status from one place. Real-time monitoring helps identify issues quickly, while automation simplifies configuration changes and reduces manual effort. These features have improved operational efficiency, reduced troubleshooting time, and helped maintain stable connectivity across the SD-WAN environment.

    One additional feature I value in Cisco Catalyst SD-WAN is the centralized dashboard, which gives a complete view of the SD-WAN environment from a single interface. It makes monitoring devices, link performance, and tunnel status much easier. The built-in troubleshooting tools reduce resolution time, and the policy-based management ensures consistent configuration across all branch locations. Overall, these features simplify day-to-day operations.

    What needs improvement?

    Cisco Catalyst SD-WAN is a strong and reliable SD-WAN solution, but there are a few areas where it could be improved. The user interface could be more intuitive for new users, and reporting and analytics could provide deeper insights with more customizable dashboards. I would also appreciate faster software upgrades, better log correlation for troubleshooting, and more built-in automation features to reduce manual configuration. It is a robust platform that has significantly improved network management and operational efficiency.

    Better documentation with real-world examples, improved third-party integration, and more detailed monitoring dashboards would make Cisco Catalyst SD-WAN even more effective.

    For how long have I used the solution?

    I have been using Cisco Catalyst SD-WAN for about one year in my current role.

    What do I think about the stability of the solution?

    Cisco Catalyst SD-WAN is stable in the market, and many more organizations can use it because it is very simple to use and has no complexity for the user. It is very straightforward for both the user and the organization because all users in any organization have few problems with it, and it is more efficient to use and much easier.

    What do I think about the scalability of the solution?

    Cisco Catalyst SD-WAN separates the control plane from the data plane. Its controller architecture is highly matured, making it one of the most valuable and reliable LAN platforms for large enterprises. This is why it has strong scalability. It can also be managed from a single dashboard for all branch locations from a single place. I do not have to travel to the branches for configuration or any troubleshooting steps. All of these steps I can do from a single place and a single dashboard.

    How are customer service and support?

    Customer support is very appreciated.

    Which solution did I use previously and why did I switch?

    We previously used a fragmented, multi-vendor legacy infrastructure combined with traditional MPLS circuits. Previously, we used a 1121 series SD-WAN router, which was impacting my organization's provisioning and management of the multiple branches from a single dashboard and from a single location. It is very amazing and useful, and very straightforward and easier to manage with every employee in the organization.

    What was our ROI?

    There is a tangible return on investment, primarily realized through a drastic reduction in network downtime and operational man-hours. The network provisioning and development time decreased by up to seventy to eighty percent. With Zero Trust provisioning via the Catalyst Center and Meraki dashboard, new branch offices are configured in hours instead of weeks, freeing engineering teams to focus on strategic initiatives rather than manual deployment. This is a benefit of Cisco Catalyst SD-WAN and it is decreasing the manual work.

    What's my experience with pricing, setup cost, and licensing?

    Cisco offers premium enterprise capabilities, but its pricing, setup cost, and licensing models represent the most significant hurdles for IT organizations. Cisco hardware commands a premium price tag compared to competitors like Juniper. Cisco provides good licensing models, and the cost is higher, but the product it is providing is amazing.

    Which other solutions did I evaluate?

    We evaluated several industry-leading SD-WAN platforms during our proof of concept.

    What other advice do I have?

    Cisco's operational efficiency in an IT environment generally involves balancing its strong central automation features against its complexity. Tools like Cisco Catalyst Center, Meraki dashboard, and Intersight offer a unified control plane. They allow network teams to push global policy changes, software updates, and configurations to hundreds of devices simultaneously, instead of managing them individually.

    Cisco optimizes the digital experience in hybrid and distributed setups by ensuring application performance, seamless collaboration, and deep visibility. Cisco achieves this optimization through three primary mechanisms. It automatically connects branch offices directly to cloud SaaS applications like Microsoft 365. Cisco SD-WAN routes traffic over the best path based on real-time latency.

    Cisco's end-to-end visibility is industry-leading, primarily due to its integration of ThousandEyes and full-stack observability across traditional network silos. Traditional monitoring stopped at the enterprise firewall, but Cisco's ThousandEyes extends visibility across the public internet, ISP, and cloud provider networks like AWS, Azure, and Google Cloud. Cisco Catalyst SD-WAN eliminates blind spots, instantly seeing outside the corporate network into the public ISP transit provider and cloud networks. Instead of chasing individual routers, engineers can pinpoint hop-by-hop latency or packet drop within seconds. A shared source of truth aggregates data across the application, security, and network, giving all teams identical metrics. System administrators, network engineers, and SaaS developers stop debating ownership and focus on identifying the problem.

    Cisco Catalyst SD-WAN has been deployed in a public cloud through Amazon Web Services. I gave this review a rating of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2847981

    New site-based policies have transformed regional control and improved uptime across locations

    Reviewed on Jun 01, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Cisco Catalyst SD-WAN has been in use for a year and a half, which is when we first started deploying it. We are now finalizing that deployment in our environment and are almost exclusively switching over from our old SD-WAN solution to the Cisco-based one.

    What is most valuable?

    I appreciate the control that we have with Cisco Catalyst SD-WAN. With the previous solution that we had, we could not build independent tunnels to each SD-WAN appliance, as they were all aggregated. Now we have considerably more freedom. We no longer have to speculate whether one thing going down means we lose an entire region of the firm; instead, everything is site-by-site based.

    Cisco Catalyst SD-WAN helps us specifically through the control of policies. With Catalyst, we are able to build out these policies at a regional level. Rather than relying on a centralized location, we have been able to distribute this across the country. We are able to target bigger regions and optimize traffic flow for those specific regions instead of being locked into whatever the previous vendor was providing us.

    What needs improvement?

    For our environment, there are some bugs with how we interpret data in terms of circuit usage, for example. This has been on our to-do list for a while because it has been broken. We have not been able to get it to work quite right specifically for our environment. We have been trying to get support and push for that resolution because for our metrics, it is valuable. Having a blank screen instead of this data can be intimidating, so we are trying to get that fixed.

    For how long have I used the solution?

    I have been working in my field professionally for about three years.

    What do I think about the stability of the solution?

    Cisco Catalyst SD-WAN has been fine for the most part. We tend to play it safe and use versions that have been tested more thoroughly, rather than necessarily old versions. Issues we might have run into stem from us being out of date, such as wanting to implement and use something that was actually on a newer version that we just had not had time to upgrade to.

    How are customer service and support?

    I would rate Cisco's operational efficiency in my IT environment very highly. At this point, we are almost an entirely Cisco-based organization, and everything that we operate on for the most part is Cisco-based. We have good support from Cisco, and I think we are happy with how everything is going.

    Which solution did I use previously and why did I switch?

    Before, our solution was VMware VeloCloud, which was then purchased by Arista recently, and that is what we are switching away from.

    How was the initial setup?

    I was not involved with the pricing, setup cost, and licensing too much. We did run into some licensing issues in the beginning, but it was through the vendor and the provider that we were using, not necessarily a Cisco thing. If that had not been involved, the process would have been smoother.

    What was our ROI?

    The increased uptime with Cisco Catalyst SD-WAN has been a return on investment.

    What other advice do I have?

    We have been focusing on fast deployment and then going back to tweak policies and figure out which features we want. I would rate this review a 10.

    View all reviews