Multi-tenancy Options
Cisco Catalyst SD-WAN supports multiple modes of segmentation in the control, data, management, and orchestration planes, as shown in Figure 2-12. One mode is dedicated tenancy. In this mode, each tenant has dedicated components, and the data plane is segmented as well. The second option is VPN tenancy. This mode segments only the data plane of the VPN topology and allows you to define read-only users who can view and monitor their VPN within SD-WAN Manager. VPN tenancy still shares the same SD-WAN components, however. The third option is multi-tenancy. With Cisco Catalyst SD-WAN multi-tenancy, a service provider can manage multiple customers, called tenants, from SD-WAN Manager. The tenants share the same set of underlying SD-WAN Control Components: SD-WAN Manager, SD-WAN Validators, and SD-WAN Controllers. The tenant data is logically isolated on these shared SD-WAN Control Components. WAN Edge devices are typically tenant specific (that is, not shared), but service providers managing a multi-tenant SD-WAN deployment may deploy a multi-tenant WAN Edge device to serve as a shared gateway for traffic belonging to multiple tenants.
Figure 2-12 Cisco Catalyst SD-WAN Multi-Tenancy Options