NOC & SOC live 24/7 Support portal
HomeInsightsWAN options
Networking

Choosing between MPLS, SD-WAN and plain internet in Iraq

The vendor comparison table assumes a carrier market that does not exist here. This is the version based on sites we actually run, including what each option costs to own over three years rather than to buy.

Every WAN comparison you will read was written for a market with several national carriers, published SLAs and a regulator that enforces them. That is not the environment we design for. In Iraq the practical constraints are different, and they change the answer.

Three of them matter more than anything in the datasheet: last-mile availability differs enormously by governorate, a single fibre cut can isolate a whole city for days, and the SLA you sign is only as good as the provider's willingness to honour it. Any design that ignores those is a design that will disappoint.

The three options, honestly described

Carrier MPLS

A private layer-3 service from a single provider connecting your sites. Predictable latency, no encryption overhead, quality of service that actually works end to end, and one company to shout at.

In practice: expensive per megabit, slow to provision, available in far fewer locations than the sales map suggests, and a single-provider dependency. When the provider has a problem, every site has the same problem at the same time. We have seen a two-day nationwide MPLS degradation take out an entire branch network that had no independent path.

SD-WAN over multiple internet circuits

Commodity broadband, fibre, microwave or LTE at each site, with an appliance that builds encrypted tunnels and chooses the best path per application in real time.

In practice: this is what we deploy most, because the failure model fits the country. Two independent circuits from two different providers, using two different physical media where possible, gives you resilience that no single MPLS service can. It is cheaper per megabit, faster to turn up, and you get central policy and per-site visibility as part of the package.

The trade-off is that you own the complexity. Someone has to run it, and if that someone is one overloaded network engineer, the platform will drift.

Plain internet with VPN

One circuit per site and IPsec tunnels back to head office. Cheapest to buy, and entirely reasonable for a small office where an outage means people go home early rather than a production line stops.

In practice: no path selection, no application awareness, and failover that depends on someone noticing. For a five-person sales office this is the right answer, and we say so. For a branch that takes payments, it is not.

What actually drives the decision

QuestionIf the answer isLean towards
What breaks when the site is offline?Revenue stopsSD-WAN, dual carrier, dual media
People are inconveniencedInternet with VPN
How many sites?Under fiveInternet with VPN, managed centrally
Fifteen or moreSD-WAN, for the central policy alone
Is there a regulator in the picture?Yes, banking or governmentMPLS core plus SD-WAN overlay
Are any sites remote or off-grid?YesSD-WAN with VSAT or LTE fallback
Who runs it day to day?Nobody dedicatedManaged SD-WAN, not a DIY build

The three-year cost, not the quotation

A quotation compares circuit prices. That is the smallest part of the picture. When we model a WAN refresh we include the circuits, the hardware refreshed at year four, the licences and support renewals, the engineering time to run it, and a realistic estimate of downtime cost.

On a recent forty-six site refresh for an energy client, MPLS looked cheaper on the first page. Over three years, the SD-WAN design came out thirty-eight per cent lower once dual-circuit resilience was priced into both options like for like. The difference was not the technology. It was that resilience on MPLS meant buying a second MPLS service, while on SD-WAN it meant buying a cheap second internet line.

The rule we apply. Design for the second circuit first. Decide how a site stays up when its primary path dies, then choose the technology that makes that affordable. Almost every WAN we have had to rescue was one that got this order backwards.

Practical notes for Iraq specifically

  • Diversify the medium, not just the provider. Two fibre circuits down the same duct are one circuit. Pair fibre with microwave or LTE.
  • Check who owns the last mile. Two providers frequently resell the same underlying infrastructure. Ask directly, and test by tracing the path.
  • Budget for power, not just connectivity. A circuit that is up while the site's router is off a generator changeover is still an outage. Put the edge kit on UPS with sensible runtime.
  • Keep VSAT for the sites that genuinely need it. Latency makes it unpleasant for interactive applications, but as a fallback that keeps a remote camp reachable it is worth every dinar.
  • Insist on out-of-band management. An LTE dongle on the console port has saved more site visits than any other single thing we deploy.

Where we usually land

For most multi-site organisations here, the answer is SD-WAN with two independent circuits per site, LTE or VSAT fallback on the remote ones, central policy, and someone contracted to actually run it. For regulated banking clients we often keep an MPLS core for the payment path and overlay SD-WAN for everything else, which satisfies the regulator without paying MPLS prices for guest Wi-Fi.

The wrong answer is a design chosen from a feature comparison without anyone visiting the sites. We survey first, every time, because the last mile is where the truth lives.

All insights Discuss your WAN