SD-WAN · SASE · full-stack networking

Connect headquarters, branches, cloud,Data centerandMobile work
Connect into oneManageablenetwork

AllowedLink assessment · application identification · routing policy · security edgeandCentralized monitoring, improve network visibility and operations across multiple sites. Assess multi-carrier links, internet access and overseas-node scenarios; verify actual coverage, providers and routes per project and contract.

MPLS · SD-WAN · SASE Multiple-carrier links (illustrative) Centralized monitoring (as contracted)
POP POINTS · DEMO
0+
COUNTRIES · DEMO
0+
AVAILABILITY · DEMO
99.99%
FAILOVER · DEMO
<0ms
yuqi intelligent · sd-wan demo DEMO
Link availability
0.00%
▲ +0.04 · last 24 hours
Average latency
0.0ms
▼ -1.8 · Shanghai–Beijing
Packet loss
0.00%
≈ 0.01 · threshold 0.1%

Node locations, counts, availability, latency, client names and case figures on this page are illustrative, not Yuqi network assets, verified results or SLA commitments.

0+ POPs · illustrative
Global nodes
0+ countries · illustrative
Coverage areas
0carriers · illustrative
China Telecom · China Mobile · China Unicom MPLS
0+ clients · illustrative
Enterprise project delivery
0.00%
SLA availability · illustrative
<0ms
Failover latency · illustrative
CONNECT · service scenarios

Four node types, one policy set

BringHeadquarters, branches, multicloud pools, private data centers, remote and mobile workBring WAN connectivity into one observable system instead of building isolated site-to-site links.

01 / HQ ↔ Branch

Headquarters and multiple branches

Geographically distributed network · dual primary/backup links

Build encrypted Overlay connections between headquarters and provincial, city and overseas branches to avoid public-internet jitter; bring branches online with zero-touch, plug-and-play deployment.

02 / Multi-Cloud

Multicloud and SaaS

Alibaba Cloud · Huawei Cloud · Tencent Cloud · AWS

Reach major public-cloud and SaaS regions through backbone POPs to avoid internet congestion, with application identification and QoS classification for SaaS.

03 / DC Interconnect

Data-center interconnection

Metro / geo-redundant active-active

Metro active-active, two-site/three-center, and disaster-recovery failover topologies built over multiple physical links for predictable operation, testing and phased rollout.

04 / Mobile & Remote

Mobile work and remote access

SASE · ZTNA

SASE-based zero-trust access assesses identity, device and location; grant least privilege by application instead of leaving VPN access wide open.

ARCHITECTURE · network overview

Understand SD-WAN at a glance

From the physical Underlay and Overlay tunnels to the control plane and security edge, each layer is shown separately for alignment with operations and IT audit.

Carrier, POP, node and route names in the architecture diagram are illustrative relationships. Actual networks, equipment and links depend on site assessment and contract scope.

Three physical network layers · visualized paths
China Telecom MPLSChina Unicom SDHChina Mobile SD-WAN
Encrypted Overlay · application-aware
Primary tunnelBackup tunnelQoS channel
Centralized orchestration · automated deployment
Control channel
Zero-trust SASE · convergence at the nearest edge
Control trafficScan / block

Underlay physical network · multiple carriers and planes

Connect through MPLS, SDH or SD-WAN from China's three major carriers, with overseas access via owned or partner POPs. Configure primary, backup, load-sharing and cold-standby links by business tier to avoid dependence on one provider.

  • MPLS backbones from China Telecom, China Unicom and China Mobile, with manageable domestic latency and jitter
  • Use the internet SD-WAN plane for resilient backup and public SaaS access
  • Illustrative international nodes in Hong Kong, Singapore, Frankfurt, London and Tokyo
CAPABILITIES · five core capabilities

Make the network visible, controllable and verifiable

Turn the traditional “as long as it connects” WAN into a measurable, schedulable system that serves the business.

Protocol counts, SLAs, latency and monitoring values in the capability diagram are illustrative, not Yuqi Intelligent network assets or performance commitments.

01 / ASSESS

Link assessment

Latency · jitter · packet loss · bandwidth utilization

Active tests + passive probes + traffic profiling establish an SLA baseline for every link and surface issues before users notice.

02 / CLASSIFY

Application identification

DPI · application profiles · traffic classification

Deep packet inspection identifies 4,000+ application protocols and classifies them by business criticality, latency sensitivity and compliance tier to inform routing policies.

03 / STEER

Routing policy

Application-aware intelligent routing

Route dynamically by application, link quality and time of day; fail over when a fault occurs with minimal user impact, and support exercises, phased changes and rollback.

04 / SECURE

Security edge

SASE · zero trust · security converged at the edge

Deploy ZTNA, SWG, CASB and FWaaS at POPs; continuously assess identity and device posture, grant least privilege per application, and avoid permanently open VPN access.

05 / OBSERVE

Centralized monitoring

Live topology · event stream · SLA reports

Manage a nationwide network from one dashboard: from port-level jitter to application latency, with live event feeds, automatic incident tickets and monthly SLA reports.

SASE · Secure Access Service Edge

SD-WAN handles connectivity
SASE handles security

SASE (Secure Access Service Edge) brings Bring users, endpoints, branches and business applications into one access-decision framework. Access is no longer granted based on “which office you are in or which circuit you use,” but Select the nearest network and security edge based on identity, device, application and risk— enablingView paths and policies separately, combine by scenario, rather than assuming all traffic follows “one fixed route.”

SASE end-to-end access path

Edge convergence
Access side → POP POP → application Security inspection results
01 · ZTNA

Zero Trust Network Access

Replace traditional VPN

Continuously assess identity, device posture, location and risk; reauthorize every access request, grant least privilege by application, and keep internal network ranges hidden by default.

02 · SWG

Secure web gateway

Web-use and threat protection

URL category filtering, antivirus, sandbox inspection and TLS-decryption inspection block malicious sites and phishing links at the edge without consuming headquarters bandwidth.

03 · CASB

Cloud access security broker

Shadow IT and data-loss prevention

Discover and manage unauthorized SaaS use; apply DLP content inspection and encryption or masking to uploads and downloads to support MLPS and industry compliance requirements.

04 · FWaaS

Firewall as a Service

Layer 7 protection and IPS

Layer 7 application identification, intrusion prevention and east-west microsegmentation; policies are centrally orchestrated in the cloud and synchronized across global POPs to avoid site-to-site drift.

One access decision, four input dimensions

Every access request carries all four attributes. The SASE policy engine reads them in real time to decide “which edge to use” and “which security policy to apply.” The same person can receive different access on different devices, in different locations and for different applications.

01 · Identity

Identity

Who is accessing: user account, organization, role, job function, project team and MFA status.

SSOMFARBACOrganization
02 · Device

Device

What is used to access: endpoint compliance, patch level, EDR status, and whether personal devices are rooted, jailbroken or unmanaged.

Compliance statusEDRPatch levelDevice fingerprint
03 · Application

Application

What is being accessed: sensitivity of the target system, whether it handles sensitive data, exposure to the internet, and bandwidth and latency requirements.

Data-sensitivity classificationData labelsSLA tierProtocol type
04 · Risk

Risk

Is the session trustworthy now? Continuously assess behavior baselines, unusual login locations, download spikes, threat-intelligence matches and session context.

Behavior baselineUEBAThreat intelligenceContinuous assessment

Decide paths and policies separately, then combine by scenario

Traditional networks assume thatAll traffic follows the same fixed route“— backhaul traffic to headquarters for centralized internet access and security inspection. SASE separates this into two independent decisions: Path layerdecides “which edge and route is fastest,” Policy layerwhile the other decides “whether access is allowed and which checks apply.” They evolve independently and can be combined by scenario.

NETWORK PATH

Path layer · How traffic is routed
Concerned only with performance and reachability, not content
  • Terminate at a nearby POP and select the lowest-latency entry point
  • MPLS private circuits / internet SD-WAN / 5G backup, with routing based on application SLAs
  • Automatically fail over when a link degrades, minimizing business impact
  • Direct local internet access for multicloud and SaaS, without routing back through headquarters
×

SECURITY POLICY

Policy layer · Is access allowed?
Concerned only with identity and content, not the route
  • ZTNA grants least-privilege access based on identity, device and risk
  • SWG / CASB / DLP inspect content and prevent data loss
  • FWaaS provides Layer 7 application identification and IPS protection
  • Cloud-orchestrated policies with atomic synchronization across global POPs
The key distinction:Changing a link does not require changing security policy, and changing policy does not require reworking the network. Add a branch, SaaS service or partner by adding a combination to the scenario matrix instead of redesigning a private circuit.

One set of building blocks, four combinations for four scenarios

Below are four examples of how network paths and security policies can be combined. The same employee may receive different access becauseIdentity, device, application and risk can vary, so the resulting route and policy can be entirely different.

Subject · application
Path layer (how traffic is routed)
Policy layer (is access allowed?)
Headquarters employee · core ERPHQ STAFF · ERP
MPLS private circuit · primary
Internet SD-WAN · backup
Application allowlist + field-level DLP + full traffic audit; endpoints must run EDR and meet patch requirements
Traveling employee · email / office appsROAMING · MAIL
Connect to the nearest POP
Automatically select the lowest-latency entry point
ZTNA authorizes each session, checks for phishing and device compliance, and exposes only email and office apps—not the internal network
Store POS · payment transactionsSTORE POS · PAYMENT
Internet primary + 5G backup
Active-active hot standby · failover < 200 ms
Microsegmentation + PCI-DSS audit + least privilege; transaction traffic uses a separate tunnel from staff internet access
Partners · collaboration platformPARTNER · COLLAB
Direct internet access
No access to the corporate network
Sandbox isolation + screen watermarking + session recording + time-limited access; only authorized documents are visible

Traditional VPN / hardware perimeter

  • All traffic backhauls through headquarters, taking the long route to SaaS from remote sites
  • One-time authentication leaves access wide open, increasing lateral-movement risk
  • Security appliances are stacked at each site, with inconsistent policies across locations
  • New branches require procurement, installation and testing, often taking months
VS

SASE edge convergence

  • Connect through a nearby POP, with local direct internet access to SaaS and public cloud
  • Continuously assess identity, device and risk for every access request
  • One policy engine · atomic policy synchronization across global POPs
  • Bring new sites online with zero-touch deployment and cloud policies delivered in seconds

Global backbone and POP locations POP International node · illustrative

Node, country and link-latency figures are illustrative, not actual backbone coverage or circuit quotes.

PEK ↔ LON · 186ms PEK ↔ SGP · 48ms SH ↔ FRA · 204ms BJ ↔ NYC · 178ms HK ↔ TYO · 36ms SZ ↔ SYD · 112ms
DELIVERY · delivery framework

From site survey through operations,
An end-to-end service that can be audited

Each phase has defined inputs, outputs and ownership boundaries; delivery can follow the implementation scope agreed by both parties.

PHASE 01 · DISCOVER

Discovery and assessment

Survey the site, profile traffic and review compliance needs to establish business requirements and the current network baseline.

  • Sampling of critical business traffic
  • Assessment report for existing SLAs
  • Compliance and security requirements review
⏱ 1–2 weeks
PHASE 02 · DESIGN

Design and validation

Architecture design, PoC validation and product selection translate the design into vendors and models.

  • High-availability topology design
  • PoC test report
  • Equipment selection list
⏱ 2–3 weeks
PHASE 03 · DEPLOY

Deployment and go-live

Receive equipment, cut over in phases and rehearse in parallel, using agreed maintenance windows and rollback criteria.

  • Phased cutover and rollback plan
  • Parallel primary/backup exercise
  • Policy deployment and acceptance
⏱ 2–4 weeks
PHASE 04 · OPERATE

Operations and optimization

Centralized monitoring, regular inspections and SLA reporting, with on-demand scaling and policy tuning.

  • Centralized monitoring (as contracted)
  • SLA report (as agreed)
  • Capacity planning and upgrades
⏱ ongoing
OUTCOMES · business outcomes

In enterprise IT planning and consulting,
What the network layer delivers

Six illustrative business-outcome measures; percentages, latency and SLAs are demo data. Confirm actual metrics against each project's acceptance criteria.

01

End-to-end network visibility

build observability across link quality, application access and endpoint experience.

VisualizedActive testingReport
02

Intelligent routing and automatic recovery

Application-level SLAs drive dynamic routing; failover in seconds aims to keep service uninterrupted.

< 200 ms failoverExercise
03

Illustrative application-level SLA definitions

Prioritize ERP, video conferencing, SaaS and other applications according to business criticality.

SLA reportApplication profile
04

Unified access for multicloud and mobile users

Unify access policies and authentication across multicloud, mobile work and remote access.

SASEZTNA
05

Converge security controls at the nearest edge

Converge access and handle threats at the POP to reduce backhaul latency and exposure.

EdgeZero trust
06

Quantifiable bandwidth and operations costs

Purchase bandwidth based on observed usage and scale it as needed instead of overprovisioning.

Cost reductionProfile
CASES · illustrative scenarios

One manageable network for different industries

Layout illustrations of three typical network scenarios (not verified client cases).

The images and figures below are industry illustrations, not verified Yuqi client projects, site photos or proof of results.

Data-center server room
Manufacturing · illustrative scenario

Connect 18 factories on one network

Replace the existing VPN; assign primary and backup links by factory tier; MES traffic uses an illustrative 99.95% SLA, while large video-inspection files use the internet SD-WAN plane.

99.95%SLA
×5Deployment speed
-32%Bandwidth cost
Financial-district network architecture
Finance · illustrative scenario

High-availability SD-WAN across two sites and three data centers

Two direct metro MPLS links, with encrypted SD-WAN tunnels between sites. Database replication uses a dedicated QoS channel; the illustrative exercise has an RTO under 60 seconds.

<60sRTO
2Metro POP
99.99%SLA
Mobile work
Retail · illustrative scenario

Zero-touch store deployment + headquarters SASE

Plug-and-play SD-WAN edge devices at stores; mobile staff connect through SASE POPs with unified zero-trust assessment.

1500+Store
15minSingle-store deployment
0VPN access open to everything
START · get started

Link-assessment scope
First, understand your network Current state and boundaries

We can discuss the scope of a network assessment based on available materials and site conditions, including link quality, application experience, SLA definitions and improvement recommendations. Deliverables and timing are subject to mutual confirmation and contract terms.

  • Confirm assessment scope and fees first
  • Report format and delivery timing as agreed by both parties
  • Testing involving multiple-carrier links (illustrative)
  • An NDA can be signed separately where confidentiality requires

Failover · routing-policy demonstration

Demonstration simulation

Primary and backup link names, RTT and status are interaction-demo data, not representations of a client circuit or SLA.