A traditional WAN is configured router by router: each site carries its own routing policy in its own CLI. SD-WAN moves that decision out of the box and into a controller. The edge routers build overlay tunnels over whatever transport exists — MPLS, broadband, LTE — and a controller tells them which traffic takes which path.
On Cisco Catalyst SD-WAN that split is formalised as four planes: the Validator (vBond) authenticates devices joining the fabric, the Manager (vManage) is where configuration and monitoring live, the Controller (vSmart) distributes routing and policy over OMP, and the WAN Edges forward the actual data. Everything hangs off a certificate model — which is why controller onboarding and certificates are where most first deployments stall, and why the courses here spend real time on them.
The other vendors reach the same outcome with different tooling: Versa builds around vDirector with multitenancy for serving several customers from one deployment, while Fortinet and Palo Alto add SD-WAN onto a firewall you may already run, so WAN policy and security policy sit on the same platform. The concepts transfer; the terminology and the failure modes do not.