Companies with 5+ locations are abandoning expensive MPLS in favor of SD-WAN on broadband internet. FortiGate dominates the segment with native security stack integration.
What SD-WAN really means
Not just load balancing on two links. Modern SD-WAN means: apps intelligently routed on the right link, sub-second failover, complete application visibility, inline security.
FortiGate SD-WAN components
- SD-WAN rules — per-app definitions: latency, jitter, packet loss
- Performance SLA — continuous measurement per link, automatic switching
- Application control — recognition of 5000+ apps
- ADVPN — dynamic full mesh between all sites
- Centralized management — FortiManager for policy push to 50+ branches
- ZTNA — Zero Trust Network Access integrated
Cost vs classic MPLS
For a 20-branch company, €5000/month MPLS becomes €1200/month SD-WAN with broadband + 4G failover. Typical ROI in 6-9 months.
What we deliver
Multi-site network design, staged 20-100 branch deployment, internal team training, operational runbook.
Example: SD-WAN rule (FortiGate CLI)
An SD-WAN zone with two links, health-check and per-app SLA:
# FortiGate SD-WAN — 2 link-uri + health-check + SLA per aplicatie
config system sdwan
set status enable
config members
edit 1
set interface "wan1"
next
edit 2
set interface "wan2"
next
end
config health-check
edit "office365"
set server "www.office.com"
set members 1 2
config sla
edit 1
set latency-threshold 50
set packetloss-threshold 1
next
end
next
end
end
SD-WAN rule with SLA
You route an app over the link that meets the SLA:
config system sdwan
config service
edit 1
set name "voip"
set mode sla
set dst "voip-servers"
config sla
edit "health"
set id 1
next
end
set priority-members 1 2
next
end
end
On-box diagnostics
You check link and SLA status from the CLI:
diagnose sys sdwan health-check
diagnose sys sdwan service
get router info routing-table all
diagnose sniffer packet any 'host 8.8.8.8' 4
ADVPN: dynamic full mesh
Tunnels between sites form automatically, on demand:
config vpn ipsec phase1-interface
edit "advpn-hub"
set type dynamic
set auto-discovery-sender enable
set auto-discovery-receiver enable
set network-overlay enable
next
end
# spoke-urile primesc shortcut-uri directe intre ele (fara sa treaca prin hub)
Central management + ZTNA
You push policies to dozens of branches and replace classic VPN with ZTNA:
# FortiManager: policy package -> install to device group 'branches'
execute central-mgmt update
# ZTNA (acces per-aplicatie, verificare postura, fara tunel de retea)
config ztna traffic-forward-proxy
edit "app-erp"
set vip "erp-vip"
next
end