Fortinet SD-WAN

Fortinet SD-WAN: the integrated architecture means the underlay is chosen on performance, not on what one carrier can supply

Fortinet SD-WAN replaces legacy WAN and fragmented VPN infrastructure with secure, application-aware FortiGate connectivity, designed, deployed and managed by Australian engineers across environments from 5 sites to 110+ in every state.

The platform difference matters less than most procurement processes assume; the provider model matters more. A telco offer stops at the network handoff and a vendor-direct model leaves operation with the internal team, while an engineering-led managed service keeps architecture, security, underlay coordination and post-go-live operation under one accountable model. The right engagement begins with an assessment of the current environment, not a hardware quote.

What this covers
One platform
SD-WAN, NGFW, ZTNA and SASE in FortiOS, not multi-vendor assembly
FortiManager from day one
Centralised policy, firmware and visibility, Australian-hosted
Multi-carrier underlay
Fibre, NBN, 4G/5G and Starlink selected per site
Applications optimised
Microsoft 365 and Teams via FortiGate ISDB application SLAs
Outcomes

Carrier-agnostic underlay, integrated security, centralised operation

Fortinet SD-WAN consolidates networking and security into a single architecture. The operational change is visible in five areas:

01 · Underlay

Carrier-agnostic underlay at every site: links selected on performance, not constrained by a single carrier’s network.

02 · Microsoft 365 and SaaS

FortiGate SD-WAN application SLAs at every site, with ISDB classifying cloud applications natively.

03 · Security policy

Centralised security policy via the Fortinet Security Fabric: SD-WAN, ZTNA and SASE as one architecture, not separate point products.

04 · Visibility and control

Every site, every link, every policy in a single console.

05 · Operation

Engineering-led managed operation: direct engineer contact, with ISP and carrier escalation managed under one accountable model.

Where this applies
5 to 110+ sitesNational and multi-state environmentsExisting FortiGate estates being modernisedVeloCloud migration following Broadcom acquisition
Fortinet is the right fit where integrated SD-WAN, firewall, centralised management and a clear path to SASE matter.
Where another architecture is genuinely better suited for the environment, we will say so.
Modernising your WAN?

Most Fortinet SD-WAN buyers are trying to solve one of these

01“MPLS contracts that no longer make economic sense.”Paying for circuit capacity that never gets used. Cost-per-megabit disproportionate to broadband alternatives at the same sites. Renewal approaching with no current alternative evaluated.
02“Microsoft 365 performance issues across branch sites.”Teams calls degrading, video and SaaS applications inconsistent over WAN links. Helpdesk cannot identify a root cause. Backhaul through a central firewall adding latency to every cloud transaction.
03“Fragmented VPN infrastructure built site by site.”Site-to-site VPN tunnels accumulated over years. Inconsistent configuration, no centralised policy, unreliable failover. Operational overhead growing with each new site.
04“Security platforms spread across multiple vendors.”No unified visibility. No consistent policy. Rising complexity at every incident escalation. Each new requirement adds another vendor relationship, another management plane and another policy console.
05“Telco-managed SD-WAN that stops at the network handoff.”No accountability for security, application performance or what happens after go-live. The carrier delivers connectivity; everything else falls back to the internal team or a separate security vendor.
Where engagements begin

Most engagements start in one of three situations: FortiGate infrastructure already in place but underused, a WAN modernisation project where Fortinet is the preferred platform, or a redesign triggered by VMware VeloCloud and Broadcom disruption. These are the operational signals we see most often.

SD-WAN never configured

Underused FortiGate

FortiGate hardware is in place, but the SD-WAN engine was never properly enabled. Branch-level routing intelligence is unused, application SLA policies have not been defined, and the platform is operating as a basic firewall, not the SD-WAN architecture the licence covers.

“We bought FortiGate years ago but the SD-WAN side was never configured.”
If any of these situations apply, a Fortinet architecture review will clarify what the current environment can support.
Where the gaps are, and what a structured FortiGate SD-WAN rollout would involve.
Why FortiGate

SD-WAN routing, firewall, ZTNA and SASE on the same operating system

Fortinet SD-WAN is not a standalone product. It is built into the FortiGate operating system. SD-WAN routing, next-generation firewall, ZTNA and SASE all run on the same platform, managed through FortiManager.

Network operating view · Fortinet fabricLive
HEAD OFFICE fibre · NBN BRANCH SITE NBN · 4G REGIONAL SITE NBN · Starlink · failover NEW SITE · ZTP 5G from day one SD-WAN FABRIC FortiGate · application-aware FORTIMANAGER every site · one console
four site types · one fabricunderlay chosen on performance →

Every site brings its own underlay mix. The fabric routes each application on the best path, security policy follows in the same process, and FortiManager sees every site, every link and every policy from one console.

When something fails at a branch, there is no blame loop between a network vendor and a security vendor: one platform, one support relationship, one team accountable for both network and security outcomes.

The real risk is not only poor link performance. It is split accountability. If one provider owns the network and another owns the firewall, incidents that cross both domains can stall between escalation paths. Fortinet reduces that architectural split by keeping SD-WAN routing and security policy inside the same FortiOS operating model.

The Fortinet architecture eliminates the split-vendor problem that slows incident resolution in multi-site WAN environments.
01

Application-aware routing

Microsoft 365, Teams and SaaS treated as priority at every site

FortiGate ISDB classifies cloud applications natively. SD-WAN policies route Microsoft 365, Teams and SaaS traffic along the best-performing path at each site, not the default route, not the cheapest path. Application SLA policies are designed for the environment and managed centrally.

Consistent M365 and Teams performance across head office, branches and remote sites.

02

Security Fabric integration

SD-WAN and firewall coordinated on the same operating system

FortiOS runs SD-WAN and next-generation firewall as one platform. When a link fails and traffic reroutes, security policy updates in the same process. There is no window where traffic moves but inspection has not followed. Branch internet access is secured from day one, not bolted on later.

One platform, one escalation path. No split-vendor finger-pointing during incidents.

03

FortiManager centralised policy

Every site, every link, every policy from one console

FortiManager is deployed as standard. Multi-site Fortinet environments without it scale linearly with operational overhead. Configuration templates, policy packages, firmware management and compliance reporting are all centralised. FortiAnalyzer aggregates logs from every managed site for incident response.

FortiManager visibility from day one is the change. The whole estate becomes legible.

04

FortiSASE-ready architecture

A clear path to SASE without redesigning the edge

FortiOS supports SASE features: ZTNA, Secure Web Gateway and CASB on existing FortiGate hardware. When security requirements mature, these activate as licensed capabilities rather than requiring a hardware refresh or a separate edge platform. The upgrade path is built in, not retrofitted.

SASE activates as a licence switch, not a rebuild project.

How we work

Same methodology across 5-site deployments and 110+ site multi-state rollouts

Whether this is a first-time FortiGate SD-WAN rollout or an extension of an existing Fortinet estate, the approach is the same: assess first, design properly, deploy in stages, and operate the environment as it grows.

01

Assess: Fortinet environment and architecture review

Comprehensive review of existing FortiGate infrastructure, FortiManager presence, current connectivity model, security policy gaps and SD-WAN readiness. The environment is documented before any hardware or licensing change is recommended.

  • FortiGate inventory: models, firmware, licence status, capacity headroom
  • FortiManager presence and centralised policy maturity
  • Per-site connectivity audit: links, ISPs, application performance baseline
  • Existing security policy review and configuration drift mapping
02

Design: FortiGate SD-WAN architecture and policy

Purpose-built SD-WAN architecture designed around site types, application profile, security requirements and growth plan. Multi-carrier access strategy is developed per site, not as a single-carrier lock-in. Underlay timing is planned from week one: Australian fibre and NBN lead times can become the project critical path if procurement starts too late.

  • Multi-carrier access per site: fibre, NBN, 4G/5G and Starlink
  • Application SLA policy design and ISDB classification mapping
  • Security Fabric and segmentation architecture
  • FortiManager and FortiAnalyzer architecture defined before rollout
03

Deploy: staged Fortinet rollout, zero disruption

FortiGate SD-WAN is deployed in parallel to the existing infrastructure. Each site is validated before cutover. Zero-touch provisioning means devices ship pre-configured and connect to FortiManager automatically on power-on. Rollback procedures are defined before every change window opens.

  • Parallel deployment alongside the existing WAN environment
  • Zero-touch provisioning for branch sites via FortiManager
  • Validated per-site cutover with rollback path defined upfront
  • Legacy SD-WAN or MPLS decommissioned only after stability is proven
04

Manage: ongoing Fortinet SD-WAN operations

Continuous link monitoring, FortiManager-based policy management, FortiGate firmware lifecycle, application performance optimisation and security posture management. Defined per-site managed service model, with ISP escalation managed by our engineers.

  • Continuous link monitoring across every site, every link
  • FortiOS firmware management and PSIRT advisory response
  • Monthly WAN health and application performance reporting
  • ISP and carrier management: direct engineer contact, not a call centre queue
The deployment is not the finish line.
FortiGate SD-WAN needs ongoing policy tuning, FortiOS firmware governance, FortiGuard service management, link monitoring, ISP escalation and FortiManager visibility after go-live. Without that operating model, the environment begins to drift as soon as the rollout is complete.
The SASE path

SASE and ZTNA extend the same architecture, not a separate edge

For organisations already running Fortinet SD-WAN, SASE and ZTNA extend the same architecture rather than forcing a separate edge redesign. FortiSASE and FortiGate-based ZTNA extend the same security policy from branch locations to remote users and cloud applications, managed through the same FortiManager console.

Most multi-vendor environments today
  • SD-WAN, firewall, ZTNA and CASB assembled from separate vendors with separate management planes
  • Multiple support relationships to coordinate during incidents
  • Edge hardware refresh required when SASE features are added
  • Security policy duplicated across consoles, drifting as the environment grows
  • Remote access handled by yet another product, typically VPN-based
Fortinet Security Fabric: one operating model
  • FortiSASE: cloud-delivered security for remote users, no separate CASB or SWG procurement
  • Fortinet ZTNA: identity-based access replacing traditional VPN, on existing FortiGate hardware
  • Consistent policy from SD-WAN branches through to cloud applications
  • SD-WAN, SASE and ZTNA as one managed architecture, not point products
  • Activation, not refresh: SASE capabilities switch on when requirements mature
Today’s SD-WAN investment supports tomorrow’s security architecture. No edge redesign required.
Organisations evaluating SASE in Australia are increasingly finding that the Fortinet integrated approach eliminates the vendor complexity of assembling best-of-breed alternatives.
Why Inlight IT

Fortinet SD-WAN deployed and operated by engineers who do this daily

01

Fortinet-specialist engineers

Network engineers with deep FortiGate, FortiManager and FortiAnalyzer experience design and lead every deployment. Not a general-purpose MSP that supports Fortinet among other platforms.

  • FortiGate, FortiManager and FortiAnalyzer engineering depth
  • Multi-site Fortinet rollout experience from 5 sites to 110+ across every Australian state
  • Direct engineer contact, not a helpdesk ticket queue

Better architecture decisions before deployment. Faster resolution when issues occur.

02

Architecture-led, not vendor-driven

Fortinet is the right platform where integrated SD-WAN, firewall and SASE matter. Where another architecture is genuinely better suited, we will say so. There is no commercial obligation to recommend Fortinet on every engagement.

  • Assessment before any hardware or licensing recommendation
  • Fortinet recommended where the environment justifies it
  • Honest platform fit, not vendor commercial bias

The right platform for the environment, not the platform that benefits us most.

03

FortiManager from day one

Multi-site Fortinet environments without FortiManager scale linearly with operational overhead. FortiManager is deployed as standard: centralised policy, firmware management and visibility built in from the start, not retrofitted.

  • FortiManager included in every multi-site deployment
  • FortiAnalyzer log aggregation across managed sites
  • Configuration templates and policy packages from day one

Centralised visibility, consistent policy, no per-site operational overhead as the estate grows.

04

Proven multi-site delivery record

Fortinet SD-WAN deployed across environments from small multi-site to 110+ site national rollouts. Underlay experience includes fibre, NBN, 4G/5G and Starlink across metro, regional and mixed-quality environments.

  • 110+ site national rollout completed across every Australian state, in under 60 days, with zero operational disruption
  • Fibre, NBN, 4G/5G and Starlink underlay experience across every site type
  • Staged migration discipline from MPLS, VeloCloud and legacy SD-WAN platforms

Proven delivery at the scale the environment requires.

05

Australian-hosted management and sovereignty

FortiManager management infrastructure, policy data and analytics are hosted in Australian data centres, including Equinix and NextDC. Network configuration and performance data remain in-country, supporting Australian data residency requirements.

  • Management hosted in Equinix and NextDC Australian facilities
  • Policy, analytics and configuration data remain in-country
  • Supports OAIC APP 8 governance and sovereignty requirements

Management plane, policy and analytics remain in-country where Australian hosting is required.

06

SASE-ready without rework

FortiGate SD-WAN architecture is designed with a clear path to SASE built in. ZTNA, Secure Web Gateway and CASB activate on existing FortiGate hardware via FortiOS: no edge redesign, no separate platform procurement, no parallel migration project.

  • FortiSASE features available on existing FortiGate hardware
  • ZTNA and SWG activated without network redesign
  • Upgrade path to full SASE without replacing the edge stack

The edge deployed today is the SASE platform activated later.

Recent work

110+ sites, every Australian state, zero operational disruption

A national distribution business operating 110+ branches across every Australian state had grown site by site through expansion and acquisition: fragmented connections, inconsistent security policy, slow troubleshooting. A single FortiGate SD-WAN fabric replaced that model.

110+
Branches and commercial sites on a single FortiGate SD-WAN fabric
Every state
One national environment, consistent policy and segmentation from day one
<60 days
Full rollout completed, zero-touch provisioning at branch sites
Zero
Branch outages during cutover across the entire migration
Day one
Real-time per-site visibility established through FortiManager
PLACEHOLDER: Beijer SD-WAN case visual
Beijer Ref Australia, national SD-WAN fabric
Refrigeration and climate technology · FortiGate SD-WAN · 110+ sites · Every Australian state
A single FortiGate SD-WAN fabric replaced the fragmented model across all 110+ locations. Consistent security policy and segmentation were enforced nationally from day one. Real-time visibility was established per site through FortiManager. The rollout completed in under 60 days with zero branch outages during cutover.
This is the difference between adding another link and operating a national branch network as one managed environment.
Read the Beijer SD-WAN case study →
Common questions

Questions Australian organisations ask before committing to Fortinet SD-WAN

Why Fortinet rather than a separate SD-WAN vendor?

Most SD-WAN vendors started as networking companies and added security as a separate layer. Fortinet built SD-WAN natively into FortiGate, with SD-WAN routing and next-generation firewall running on the same operating system. When an incident occurs, there is no blame loop between a network vendor and a security vendor: one platform, one support relationship, one team accountable for both network and security outcomes.

Do we need to replace our existing FortiGate firewalls to deploy SD-WAN?

In most cases, no. Fortinet SD-WAN is a licensed capability within FortiOS. If FortiGate devices are running current firmware and have adequate hardware capacity, SD-WAN can typically be configured without replacing existing hardware. The assessment reviews the existing environment before any hardware change is recommended. We will not recommend new hardware unless the assessment confirms it is necessary.

What is FortiManager and why does it matter for multi-site deployments?

FortiManager is Fortinet’s centralised management platform for FortiGate devices. Without it, multi-site environments are managed site-by-site: every policy change and firmware update requires per-device intervention. FortiManager allows every site, link and policy to be managed from a single console. Our deployments include FortiManager as standard, with centralised visibility and consistent policy enforcement from day one.

How disruptive is a FortiGate SD-WAN deployment to live operations?

Properly structured, zero disruption. Our methodology is staged: assess and document the current environment first, design the target architecture, then deploy in controlled phases with rollback capability at each step. The most common disruption risk is undocumented existing configuration. The assessment phase surfaces those gaps before any changes are made.

How disruptive is cutover for live branch operations?

Cutover is the highest-risk moment in a live SD-WAN migration, so it is planned before any change window opens. FortiGate SD-WAN is deployed in parallel with the existing environment first. Each site is validated against agreed application, failover and security baselines before production traffic is moved. Rollback is defined before the change window, and after-hours cutover is standard for production sites. Most branches experience no user impact when the work is staged properly. Cutover is typically completed in under an hour per site, subject to site complexity, underlay readiness and existing configuration quality.

How does zero-touch provisioning work with Fortinet?

Hardware ships from the manufacturer pre-registered to your FortiManager instance. When a device powers on at a branch site, it connects to FortiManager over the internet, authenticates and downloads its full configuration automatically. No pre-configuration by a technician on site. The branch joins the SD-WAN fabric within minutes of being powered on. This is what makes 110+ site deployments in under 60 days operationally possible.

What is FortiSASE and do we need it now?

FortiSASE adds cloud-delivered ZTNA, secure web gateway and CASB to the SD-WAN foundation. FortiGate supports SASE features under FortiOS, which means they can be activated on existing hardware when security requirements mature. SASE is not required on day one, but the Fortinet architecture does not require a hardware refresh to get there. The upgrade path is built in from the start.

How much does Fortinet SD-WAN cost?

Indicative range: typically in the range of $300 to $800 per site per month for smaller multi-site deployments, including hardware, licensing and managed service. Larger distributed deployments of 50 or more sites typically start from $150 per site per month with volume pricing. Actual cost is subject to site count, underlay options, FortiGate hardware sizing, FortiGuard subscription bundle and managed service scope. The relevant comparison is total cost against current MPLS circuit spend plus internal IT overhead. A site audit is completed before any commercial proposal so the estimate reflects the actual Fortinet environment.

Can Fortinet SD-WAN work with our existing links?

Yes. Fortinet SD-WAN can work with existing NBN, fibre, broadband, 4G/5G, Starlink and MPLS links. The review identifies the best underlay mix per site. Existing connections do not need to be replaced before the architecture is understood.

What happens if we exit VeloCloud or another SD-WAN platform?

Organisations exiting VMware VeloCloud following the Broadcom acquisition often need an SD-WAN redesign without disrupting live operations. We provide migration assessment, FortiGate SD-WAN architecture redesign and staged cutover planning. The previous environment continues to operate during the transition. Rollback procedures are defined before every change window. MPLS or legacy SD-WAN is decommissioned at each site only after the FortiGate environment has been stable under production load.

Practical next step

Find out what Fortinet SD-WAN would improve in your environment

Discuss Fortinet SD-WAN