What is a WAN?
A wide area network (also called a WAN, or Wide Area Network) is a network that connects distant sites to each other, without being limited to a single location. WANs can support communication, information sharing and much more between sites that are far apart, through a telecommunications operator.
WANs serve companies spread over several sites as well as everyday uses: the Internet is itself the largest wide area network in existence.
This page sets out what the term covers: the place of the WAN compared to other networks, the vocabulary used by operators during a connection, the access technologies available, the protocols that travel over these links, and the criteria used to compare two offers. It ends with a case of connecting three sites of the same company.
The WAN compared to the LAN and the MAN
Three acronyms classify a network according to its geographical extent. They differ not only in the distance covered: above all, they differ in the answer to two questions. Who owns the cables? Who operates the link and repairs it in the event of a failure?
The LAN, local area network
The LAN (Local Area Network) covers a building or a site: a floor, a workshop, a campus. The cables, the switches and the Wi-Fi access points belong to the company, which installs and replaces them itself. Common data rates are counted in gigabits per second, and the delivery delay between two machines in fractions of a millisecond. The cost is a hardware purchase, not a subscription.
The MAN, metropolitan area network
The MAN (Metropolitan Area Network) connects several sites in the same urban area: the buildings of a local authority, the sites of a hospital, the campuses of a university. The medium is often optical fiber laid or leased at the scale of the city, sometimes in the form of dark fiber, that is to say a bare fiber leased without active equipment, on which the customer installs its own transmitters and receivers. Ownership of the medium is shared or delegated here: this is the intermediate situation between the LAN and the WAN.
The WAN, wide area network
The WAN begins where the company stops laying its own cables. Connecting a site in Lille to a site in Toulouse means crossing public land on which no one, apart from a licensed operator, can intervene. The company therefore no longer buys a cable: it subscribes to a service. It no longer controls the path taken by its data, nor the equipment crossed, nor the repair time. What it buys in exchange is a written commitment.
This is the most important shift to understand: moving from the LAN to the WAN means moving from a network that you repair yourself to a network that you have repaired under contract.
- Reach: from a building to a campus, that is from a few tens of meters to a few kilometers for the LAN, the scale of an urban area for the MAN, no limit in principle for the WAN.
- Ownership of the medium: the company for the LAN, the company or a local authority for the MAN, an operator for the WAN.
- Operation: internal team for the LAN, service contract for the WAN.
- Data rate: plentiful and inexpensive in the LAN, counted and billed monthly in the WAN.
- Restoration time: it depends on the spare parts kept on site in the LAN, on a contractual clause in the WAN.
The local loop and the vocabulary of the connection
The local loop is the segment that connects the subscriber site to the first piece of operator equipment. On telephone copper, this equipment is located at the NRA (nœud de raccordement d’abonnés, the subscriber connection node); on optical fiber, at the NRO (nœud de raccordement optique, the optical connection node). This same segment is commonly called the last mile.
This last mile is the most expensive and the slowest part of the whole chain to produce: it requires civil engineering work, road authorizations, sometimes a trench. This is the reason why a dedicated fiber connection may be announced with a lead time of several months, while the core of the operator network is already in place.
DTE and DCE
Two roles share the end of a link. The DTE (Data Terminal Equipment) is the equipment that produces and consumes the data: in practice, the customer router. The DCE (Data Circuit-terminating Equipment) is the equipment that adapts this data to the transmission medium and provides the clock of the link: modem, optical converter, termination unit installed by the operator.
The distinction is not decorative. It designates responsibilities: the DCE side falls to the operator, the DTE side falls to the customer. On older-generation serial links, it had a direct technical consequence, the DCE imposing the clock rate to which the DTE had to align.
The demarcation point
The demarcation point is the contractual boundary between the operator network and the customer installation. In France, on a copper line, it is the DTI (dispositif de terminaison intérieur, the indoor termination device), a small strip fixed to the wall at the entrance of the building. On optical fiber, it is the PTO (point de terminaison optique, the optical termination point), the optical wall socket.
Any work on a failure begins by determining on which side of this point the fault lies, by connecting a test device directly to the socket. Without this check, the exchange with operator support turns into one assertion against another. Locating and photographing this point on each site, before any failure occurs, saves a considerable amount of time when the day comes.
Access technologies, from yesterday to today
What belongs to history
The RTC (réseau téléphonique commuté, the switched telephone network) served as the first data access: a modem converted the data into audible signals on an ordinary telephone line, up to a few tens of kilobits per second, the line being busy for the whole duration of the communication. ISDN (Integrated Services Digital Network, in French RNIS) made this line digital. Its basic access, called T0, offered two channels of 64 kilobits per second for data or voice, plus a separate channel for signaling; its primary access, called T2, offered thirty of them in Europe. ISDN long served as an automatic backup for corporate data links. In France, the shutdown of the RTC has been under way since 2018 and is continuing area by area; the date applicable to a given site is checked with the operator.
Frame Relay and ATM (Asynchronous Transfer Mode) then structured corporate networks. Frame Relay carried data in virtual circuits identified by a DLCI (Data Link Connection Identifier), with a contractual data rate called the CIR (Committed Information Rate) and a tolerance for exceeding it beyond that. ATM divided traffic into fixed-size cells of 53 bytes, 48 of which were useful data, which allowed regular multiplexing of voice and data. Neither of these two technologies appears any longer in the catalogs of French operators for a new subscription, but their vocabulary has survived: virtual circuit, guaranteed data rate and class of service are found as such in current offers.
xDSL
xDSL is the name of the family of digital transmissions over the telephone copper pair. ADSL is asymmetric: the downstream rate, toward the subscriber, is markedly higher than the upstream rate. SDSL is symmetric, at a more modest but identical rate in both directions, which suits a site that hosts a service or sends backups. VDSL2 increases the data rate on short lines only.
The decisive point is that the data rate depends on the length and the condition of the copper pair between the site and the NRA. It cannot be promised: it is established by the line test, then at service commissioning. A data rate announced on a commercial leaflet is a theoretical maximum.
Fiber: FTTH and FTTO
FTTH (Fiber To The Home) is the name of consumer fiber access, also sold to small business sites. It is most often built according to what is called a shared architecture, where a single fiber coming from the NRO is shared between several subscribers by means of optical splitters. The data rate is high, often asymmetric, without any guarantee, and the repair time is that of a standard offer.
FTTO (Fiber To The Office), also called dedicated fiber or business fiber, is a point-to-point link between the site and the operator, without sharing. The data rate is symmetric and guaranteed, a restoration time appears in the contract, and fixed IP addresses are provided. The price gap with FTTH is counted in multiples.
The difference between the two is not visible in a data rate measurement carried out on a Tuesday afternoon, where the shared access may show more. It becomes visible during an outage occurring outside working hours, when only a contractual restoration commitment triggers the intervention of the operator.
The leased line
A leased line, also called a dedicated line, is a permanent link reserved between two points, billed at a flat rate regardless of the traffic carried. Delivered today in Ethernet over fiber, it is used when two sites must behave as though they were on the same local network: the operator then carries the layer 2 frames from one site to the other, without intermediate routing visible to the customer. It is a solution used to connect a backup server room to its main room.
4G and 5G as backup access
A router fitted with a SIM card makes it possible to switch automatically to a mobile access when the main access disappears. The limits must be known before relying on it: capped monthly volume, data rate that varies with the load of the cell and the quality of reception inside the building, and an address that is most often shared between several subscribers, which makes it impossible to reach a service hosted on the site from outside.
Two precautions are required. Coverage is checked with the unit placed in its final location and its antenna in place, not with a telephone held near a window. And the switchover is tested deliberately, at regular intervals: a backup that has never been tried is a backup that is only assumed.
MPLS and SD-WAN
MPLS
MPLS (Multiprotocol Label Switching) is a technique used inside the operator network. At the entry point, the router attaches a label to the packet; the following routers switch on the basis of this label instead of consulting their entire IP routing table.
For the customer, the value lies not in the switching speed but in what the label makes possible: the operator builds an MPLS VPN, that is to say a network where the sites of a single customer exchange with each other using their own addressing plan, separated from other customers, and where several classes of service can be reserved, for example a priority queue for telephony.
Two points are frequently misunderstood. An MPLS VPN is private but is not encrypted: the separation is logical and rests on the configuration of the operator, not on cryptography; if the data must be encrypted, encryption is added on top. Moreover, an MPLS access does not provide Internet access by itself: the Internet exit is a separate service, usually centralized on one or two sites of the customer.
SD-WAN
SD-WAN (Software-Defined WAN) is the name of an arrangement where each site receives a unit that aggregates several accesses — fiber, xDSL, mobile — and sets up encrypted tunnels toward the other sites, forming an overlay layer above the existing accesses. A central console distributes the policy: which application takes which link, in which order of preference, and from which threshold of loss or latency the switchover takes place.
What this approach changes: the backup link is no longer dormant, it carries traffic; the switchover is decided on a quality measured continuously and not on the mere disappearance of the link; the configuration is entered once in the console instead of being repeated site by site. What it does not change: the quality of the underlying accesses. Two accesses without a guarantee remain two accesses without a guarantee. SD-WAN distributes and monitors, it does not manufacture a commitment where the contract contains none.
The link protocols used on WAN trunks
On a local network, the link layer is almost always Ethernet. On wide area links, in particular serial ones, other protocols encapsulate the IP packets. Two names recur in the configurations and the documentation of serial links, which are still present on older connections.
HDLC
HDLC (High-Level Data Link Control) is a link protocol standardized by ISO. It delimits frames with flags and checks their integrity with a cyclic redundancy code. Its standardized version does not provide a field indicating which protocol is carried in the frame; several manufacturers, including Cisco, therefore defined a proprietary variant that adds this field. The consequence is practical: two routers from different brands configured in HDLC do not necessarily understand each other, whereas PPP is interoperable.
PPP
PPP (Point-to-Point Protocol) is the most widely used point-to-point link protocol on the accesses of Internet service providers. It is made up of LCP (Link Control Protocol), which establishes the link, tests it and negotiates its parameters, and of a family of NCP (Network Control Protocol) protocols, including IPCP (IP Control Protocol) for IP, which negotiates in particular the assignment of an address. It also provides subscriber authentication, historically with PAP (Password Authentication Protocol), which transmits the password in clear text, and with CHAP (Challenge Handshake Authentication Protocol), which proceeds by challenge and response. This last function explains its longevity with Internet service providers.
PPP has outlived the medium on which it was born: on xDSL accesses, it is most often carried in PPPoE (PPP over Ethernet), sometimes in PPPoA (PPP over ATM) on older accesses. This encapsulation consumes eight bytes, so that the MTU (Maximum Transmission Unit, the maximum size of data that can be carried in a frame) drops from 1500 to 1492 bytes. This is the classic cause of pages that load halfway and of transfers that freeze while ping answers normally. The fix consists in having the router adjust the announced TCP segment size, called the MSS (Maximum Segment Size), to the value that the link actually accepts.
The site-to-site VPN: a WAN built on the Internet
A site-to-site VPN (Virtual Private Network) consists in setting up an encrypted tunnel between the routers of two sites, across the Internet. The two local networks then behave as though they were connected by a private link, without any cable having been laid between them. It is a widespread way of building a corporate WAN when the budget does not allow a guaranteed operator service to be subscribed.
IPsec (Internet Protocol Security) is the set of protocols most used for this. It works in two stages.
- The negotiation, handled by IKE (Internet Key Exchange, in its IKEv2 version): the two ends first agree on the algorithms and exchange the elements used to build the keys, then authenticate each other, with a shared secret or with a certificate.
- The transport, handled by ESP (Encapsulating Security Payload), which encrypts and authenticates each packet. In tunnel mode, the original packet is encapsulated whole in a new packet whose source and destination addresses are those of the two gateways.
The points to watch are always the same. The addressing plans of the sites must not overlap, otherwise a workstation will not know whether a given address designates a local machine or a remote one. The encapsulation reduces the space available in each packet: the MTU and the MSS must again be adjusted on the tunnel interfaces. The two ends must offer compatible algorithms, failing which the negotiation fails and the tunnel never comes up. Finally, the path taken remains the Internet: the tunnel guarantees confidentiality and integrity, never the delivery delay.
What to look at when choosing a link
Guaranteed or non-guaranteed data rate
A non-guaranteed data rate, known as best effort, is a theoretical maximum reached when conditions allow, on a shared resource. A guaranteed data rate is a commitment by the operator on a floor value, generally symmetric, maintained at all times. The price gap between the two arrangements is large, and it is this gap, and not the figure displayed, that distinguishes a business offer from a consumer offer. The question to ask the provider is therefore not "what data rate?" but "what share of this data rate is contractual?".
Latency and jitter
Latency is the delivery delay of a packet; in practice it is measured over a round trip, with the ping command. Part of it cannot be reduced: light travels in a fiber at about 200,000 kilometers per second, that is roughly one millisecond every 200 kilometers and in one direction only. The rest comes from the equipment crossed and from the queues. Jitter is the variation of this latency from one packet to the next; it is jitter, more than latency itself, that breaks up a telephone conversation.
The GTR
The GTR (garantie de temps de rétablissement, the guaranteed restoration time) is the maximum contractual delay between the reporting of a failure and its restoration, with penalties if it is exceeded. Three elements are read together: the announced duration, the time range during which it applies — working hours, or else 24 hours a day and 7 days a week — and the starting point of the count, which is the filing of the ticket and not the moment when the failure began.
An offer without a GTR is not an offer whose GTR would be long: it is an absence of commitment, with a repair time that may be counted in working days.
Redundancy of the access
A second link is a backup only if it shares nothing with the first. The list is gone through point by point: two separate operators, two separate technologies, two physical entry points into the building, two different civil engineering routes, two routers, two power supplies. Two subscriptions taken out with two operators but running through the same duct under the same road fail together, and the doubled bill will have bought an illusion. The question of whether the two links are physically separate is put in writing to the operator, who knows how to handle it.
Three commands are enough to establish a first assessment of a link, from a workstation connected behind the site router. The address used here belongs to a range reserved for documentation and must be replaced by that of the destination actually observed.
ping -c 5 192.0.2.1
traceroute 192.0.2.1
ping -c 3 -M do -s 1472 192.0.2.1
The first measures the round-trip delay and the loss. The second displays the routers crossed, which makes it possible to locate a degradation. The third sends a packet of maximum size without allowing it to be fragmented: 1472 bytes of data plus the headers correspond to 1500 bytes, the standard size on Ethernet. If it fails while the first succeeds, the path accepts a smaller packet size, which brings us back to the MTU adjustment mentioned above.
Example of a build: connecting three sites of the same company
A company has a head office, where the servers and the Internet exit are located, and two branches of about ten workstations each, situated in two other regions. The branches use an application hosted at the head office as well as IP telephony. Here is one possible build and the reason for each choice.
The accesses
- At the head office, a dedicated FTTO fiber with a guaranteed symmetric data rate, with a GTR of four hours applicable 24 hours a day and 7 days a week. This site is the concentration point: if it fails, all three sites are out of service. That is therefore where the contractual commitment is paid for.
- In each branch, a shared fiber or xDSL access depending on the eligibility established, supplemented by a mobile backup access on a separate router.
- At the head office as well, a second access subscribed with another operator and on another technology, so that an incident at one operator does not cut off all three sites at once.
The interconnection
An IPsec tunnel is set up from each branch toward the head office, which gives a star topology: the head office is the center, the branches the arms. If the two branches exchange a great deal of traffic with each other, a direct tunnel between the two avoids the detour through the head office and the delay it adds.
The choice between this arrangement and an MPLS VPN subscribed with an operator turns on two points: the need for a quality of service guaranteed end to end, which argues for MPLS, and the cost, which argues for IPsec over Internet accesses. There is no right answer out of context. With three sites and about ten workstations per branch, the IPsec build covers the need as long as no end-to-end guarantee is required by the business activity.
Addressing and routing
The addressing plan is divided site by site, without overlap, reserving ranges for future sites from the outset: reworking an addressing plan afterwards, once the tunnels are in production, costs far more than planning it. With three sites, static routes are enough and are easy to read back. Beyond that, or as soon as a site has two possible paths toward the same destination, a dynamic routing protocol inside the tunnels avoids maintaining these routes by hand.
What must not be left out
- Prioritizing voice on each access, applied in the outgoing direction: you can only give priority to the traffic that you send yourself, the incoming direction is endured unless the operator provides a specific service.
- Adjusting the MTU and the MSS on the tunnel interfaces, on all three sites.
- Name resolution, so that the branches reach the internal services by name, including during a switchover to the backup link.
- Monitoring of the links — availability, latency, loss rate — which serves to establish failures before the users do and to have dated measurements available during exchanges with the operator.
- Periodic testing of the switchover to backup, in real conditions and at a chosen time.
- The operating references: line number, contract reference, operator support number, recorded outside the information system that they are precisely meant to repair.
Points to watch and what comes next
A summary that can be used before signing an offer or taking over an existing WAN.
- Record for each site the access in place, the downstream and upstream data rates, the guaranteed or non-guaranteed status, the GTR and its time range.
- Physically locate the demarcation point of each site, and document it with a photograph.
- Check that the backup links share neither operator, nor technology, nor entry point into the building.
- Check that there is no overlap in the addressing plan, including for the sites to come.
- Measure the latency and the loss rate between sites during busy periods, and keep these readings as a reference.
- Record the date of the last switchover test actually carried out on each backup.
Two mistakes come up regularly. The first consists in confusing data rate with quality: a high-speed access without a commitment does not replace a slower access that comes with a GTR, as soon as the business activity stops when the link goes down. The second consists in regarding redundancy as acquired because two subscriptions appear on the bill, without having checked the physical routing of the two links.
Three subjects follow on directly from this one and deserve to be studied next: routing, static and then dynamic with OSPF (Open Shortest Path First) and BGP (Border Gateway Protocol); quality of service, that is to say the classification and queuing of traffic on a saturated link; and securing the accesses, with the firewall placed in line, the filtering of outgoing traffic and the retention of logs.
The original text of this article was not preserved by the web archives: the capture of the page stops before the body. Only its introduction remains, taken up here as the opening. The rest was rewritten on September 9, 2026, then reviewed and corrected point by point.
