Fortinet SD-WAN: the integrated architecture means the underlay is chosen on performance, not on what one carrier can supply
Fortinet SD-WAN replaces legacy WAN and fragmented VPN infrastructure with secure, application-aware FortiGate connectivity, designed, deployed and managed by Australian engineers across environments from 5 sites to 110+ in every state.
The platform difference matters less than most procurement processes assume; the provider model matters more. A telco offer stops at the network handoff and a vendor-direct model leaves operation with the internal team, while an engineering-led managed service keeps architecture, security, underlay coordination and post-go-live operation under one accountable model. The right engagement begins with an assessment of the current environment, not a hardware quote.
Carrier-agnostic underlay, integrated security, centralised operation
Fortinet SD-WAN consolidates networking and security into a single architecture. The operational change is visible in five areas:
Carrier-agnostic underlay at every site: links selected on performance, not constrained by a single carrier’s network.
FortiGate SD-WAN application SLAs at every site, with ISDB classifying cloud applications natively.
Centralised security policy via the Fortinet Security Fabric: SD-WAN, ZTNA and SASE as one architecture, not separate point products.
Every site, every link, every policy in a single console.
Engineering-led managed operation: direct engineer contact, with ISP and carrier escalation managed under one accountable model.
Most Fortinet SD-WAN buyers are trying to solve one of these
Most engagements start in one of three situations: FortiGate infrastructure already in place but underused, a WAN modernisation project where Fortinet is the preferred platform, or a redesign triggered by VMware VeloCloud and Broadcom disruption. These are the operational signals we see most often.
SD-WAN never configured
Underused FortiGateFortiGate hardware is in place, but the SD-WAN engine was never properly enabled. Branch-level routing intelligence is unused, application SLA policies have not been defined, and the platform is operating as a basic firewall, not the SD-WAN architecture the licence covers.
M365 at branches
Performance inconsistentTeams calls degrade, file synchronisation lags, and the helpdesk cannot identify a root cause. The FortiGate ISDB classifications and application SLA policies that would address this have not been applied at site level.
Policy drift
Inconsistent securityEach site was configured separately over time. Different policies, different inspection profiles, different firmware versions. No central oversight. Policy drift between sites has become operationally significant.
No FortiManager
Device-by-device opsMulti-site FortiGate environments without FortiManager are managed device-by-device. Every policy change and firmware update is a per-site intervention. Centralised visibility, change control and reporting are absent. The environment scales linearly with operational overhead.
Acquisition sprawl
Inherited estatesNew sites are inherited rather than designed. Each acquired environment had its own approach to FortiGate configuration. Integrating them into a coherent architecture without redesign-from-scratch is the operational challenge.
VeloCloud exit
Broadcom disruptionOrganisations exiting VMware VeloCloud after the Broadcom acquisition need a new SD-WAN platform without disrupting live operations. Migration assessment, FortiGate architecture redesign and staged cutover planning become urgent rather than optional.
SD-WAN routing, firewall, ZTNA and SASE on the same operating system
Fortinet SD-WAN is not a standalone product. It is built into the FortiGate operating system. SD-WAN routing, next-generation firewall, ZTNA and SASE all run on the same platform, managed through FortiManager.
Every site brings its own underlay mix. The fabric routes each application on the best path, security policy follows in the same process, and FortiManager sees every site, every link and every policy from one console.
When something fails at a branch, there is no blame loop between a network vendor and a security vendor: one platform, one support relationship, one team accountable for both network and security outcomes.
The real risk is not only poor link performance. It is split accountability. If one provider owns the network and another owns the firewall, incidents that cross both domains can stall between escalation paths. Fortinet reduces that architectural split by keeping SD-WAN routing and security policy inside the same FortiOS operating model.
Application-aware routing
Microsoft 365, Teams and SaaS treated as priority at every site
FortiGate ISDB classifies cloud applications natively. SD-WAN policies route Microsoft 365, Teams and SaaS traffic along the best-performing path at each site, not the default route, not the cheapest path. Application SLA policies are designed for the environment and managed centrally.
Consistent M365 and Teams performance across head office, branches and remote sites.
Security Fabric integration
SD-WAN and firewall coordinated on the same operating system
FortiOS runs SD-WAN and next-generation firewall as one platform. When a link fails and traffic reroutes, security policy updates in the same process. There is no window where traffic moves but inspection has not followed. Branch internet access is secured from day one, not bolted on later.
One platform, one escalation path. No split-vendor finger-pointing during incidents.
FortiManager centralised policy
Every site, every link, every policy from one console
FortiManager is deployed as standard. Multi-site Fortinet environments without it scale linearly with operational overhead. Configuration templates, policy packages, firmware management and compliance reporting are all centralised. FortiAnalyzer aggregates logs from every managed site for incident response.
FortiManager visibility from day one is the change. The whole estate becomes legible.
FortiSASE-ready architecture
A clear path to SASE without redesigning the edge
FortiOS supports SASE features: ZTNA, Secure Web Gateway and CASB on existing FortiGate hardware. When security requirements mature, these activate as licensed capabilities rather than requiring a hardware refresh or a separate edge platform. The upgrade path is built in, not retrofitted.
SASE activates as a licence switch, not a rebuild project.
Same methodology across 5-site deployments and 110+ site multi-state rollouts
Whether this is a first-time FortiGate SD-WAN rollout or an extension of an existing Fortinet estate, the approach is the same: assess first, design properly, deploy in stages, and operate the environment as it grows.
Assess: Fortinet environment and architecture review
Comprehensive review of existing FortiGate infrastructure, FortiManager presence, current connectivity model, security policy gaps and SD-WAN readiness. The environment is documented before any hardware or licensing change is recommended.
- FortiGate inventory: models, firmware, licence status, capacity headroom
- FortiManager presence and centralised policy maturity
- Per-site connectivity audit: links, ISPs, application performance baseline
- Existing security policy review and configuration drift mapping
Design: FortiGate SD-WAN architecture and policy
Purpose-built SD-WAN architecture designed around site types, application profile, security requirements and growth plan. Multi-carrier access strategy is developed per site, not as a single-carrier lock-in. Underlay timing is planned from week one: Australian fibre and NBN lead times can become the project critical path if procurement starts too late.
- Multi-carrier access per site: fibre, NBN, 4G/5G and Starlink
- Application SLA policy design and ISDB classification mapping
- Security Fabric and segmentation architecture
- FortiManager and FortiAnalyzer architecture defined before rollout
Deploy: staged Fortinet rollout, zero disruption
FortiGate SD-WAN is deployed in parallel to the existing infrastructure. Each site is validated before cutover. Zero-touch provisioning means devices ship pre-configured and connect to FortiManager automatically on power-on. Rollback procedures are defined before every change window opens.
- Parallel deployment alongside the existing WAN environment
- Zero-touch provisioning for branch sites via FortiManager
- Validated per-site cutover with rollback path defined upfront
- Legacy SD-WAN or MPLS decommissioned only after stability is proven
Manage: ongoing Fortinet SD-WAN operations
Continuous link monitoring, FortiManager-based policy management, FortiGate firmware lifecycle, application performance optimisation and security posture management. Defined per-site managed service model, with ISP escalation managed by our engineers.
- Continuous link monitoring across every site, every link
- FortiOS firmware management and PSIRT advisory response
- Monthly WAN health and application performance reporting
- ISP and carrier management: direct engineer contact, not a call centre queue
SASE and ZTNA extend the same architecture, not a separate edge
For organisations already running Fortinet SD-WAN, SASE and ZTNA extend the same architecture rather than forcing a separate edge redesign. FortiSASE and FortiGate-based ZTNA extend the same security policy from branch locations to remote users and cloud applications, managed through the same FortiManager console.
- SD-WAN, firewall, ZTNA and CASB assembled from separate vendors with separate management planes
- Multiple support relationships to coordinate during incidents
- Edge hardware refresh required when SASE features are added
- Security policy duplicated across consoles, drifting as the environment grows
- Remote access handled by yet another product, typically VPN-based
- FortiSASE: cloud-delivered security for remote users, no separate CASB or SWG procurement
- Fortinet ZTNA: identity-based access replacing traditional VPN, on existing FortiGate hardware
- Consistent policy from SD-WAN branches through to cloud applications
- SD-WAN, SASE and ZTNA as one managed architecture, not point products
- Activation, not refresh: SASE capabilities switch on when requirements mature
Fortinet SD-WAN deployed and operated by engineers who do this daily
01Fortinet-specialist engineers
Network engineers with deep FortiGate, FortiManager and FortiAnalyzer experience design and lead every deployment. Not a general-purpose MSP that supports Fortinet among other platforms.
- FortiGate, FortiManager and FortiAnalyzer engineering depth
- Multi-site Fortinet rollout experience from 5 sites to 110+ across every Australian state
- Direct engineer contact, not a helpdesk ticket queue
Better architecture decisions before deployment. Faster resolution when issues occur.
02Architecture-led, not vendor-driven
Fortinet is the right platform where integrated SD-WAN, firewall and SASE matter. Where another architecture is genuinely better suited, we will say so. There is no commercial obligation to recommend Fortinet on every engagement.
- Assessment before any hardware or licensing recommendation
- Fortinet recommended where the environment justifies it
- Honest platform fit, not vendor commercial bias
The right platform for the environment, not the platform that benefits us most.
03FortiManager from day one
Multi-site Fortinet environments without FortiManager scale linearly with operational overhead. FortiManager is deployed as standard: centralised policy, firmware management and visibility built in from the start, not retrofitted.
- FortiManager included in every multi-site deployment
- FortiAnalyzer log aggregation across managed sites
- Configuration templates and policy packages from day one
Centralised visibility, consistent policy, no per-site operational overhead as the estate grows.
04Proven multi-site delivery record
Fortinet SD-WAN deployed across environments from small multi-site to 110+ site national rollouts. Underlay experience includes fibre, NBN, 4G/5G and Starlink across metro, regional and mixed-quality environments.
- 110+ site national rollout completed across every Australian state, in under 60 days, with zero operational disruption
- Fibre, NBN, 4G/5G and Starlink underlay experience across every site type
- Staged migration discipline from MPLS, VeloCloud and legacy SD-WAN platforms
Proven delivery at the scale the environment requires.
05Australian-hosted management and sovereignty
FortiManager management infrastructure, policy data and analytics are hosted in Australian data centres, including Equinix and NextDC. Network configuration and performance data remain in-country, supporting Australian data residency requirements.
- Management hosted in Equinix and NextDC Australian facilities
- Policy, analytics and configuration data remain in-country
- Supports OAIC APP 8 governance and sovereignty requirements
Management plane, policy and analytics remain in-country where Australian hosting is required.
06SASE-ready without rework
FortiGate SD-WAN architecture is designed with a clear path to SASE built in. ZTNA, Secure Web Gateway and CASB activate on existing FortiGate hardware via FortiOS: no edge redesign, no separate platform procurement, no parallel migration project.
- FortiSASE features available on existing FortiGate hardware
- ZTNA and SWG activated without network redesign
- Upgrade path to full SASE without replacing the edge stack
The edge deployed today is the SASE platform activated later.
110+ sites, every Australian state, zero operational disruption
A national distribution business operating 110+ branches across every Australian state had grown site by site through expansion and acquisition: fragmented connections, inconsistent security policy, slow troubleshooting. A single FortiGate SD-WAN fabric replaced that model.
Questions Australian organisations ask before committing to Fortinet SD-WAN
Why Fortinet rather than a separate SD-WAN vendor?
Most SD-WAN vendors started as networking companies and added security as a separate layer. Fortinet built SD-WAN natively into FortiGate, with SD-WAN routing and next-generation firewall running on the same operating system. When an incident occurs, there is no blame loop between a network vendor and a security vendor: one platform, one support relationship, one team accountable for both network and security outcomes.
Do we need to replace our existing FortiGate firewalls to deploy SD-WAN?
In most cases, no. Fortinet SD-WAN is a licensed capability within FortiOS. If FortiGate devices are running current firmware and have adequate hardware capacity, SD-WAN can typically be configured without replacing existing hardware. The assessment reviews the existing environment before any hardware change is recommended. We will not recommend new hardware unless the assessment confirms it is necessary.
What is FortiManager and why does it matter for multi-site deployments?
FortiManager is Fortinet’s centralised management platform for FortiGate devices. Without it, multi-site environments are managed site-by-site: every policy change and firmware update requires per-device intervention. FortiManager allows every site, link and policy to be managed from a single console. Our deployments include FortiManager as standard, with centralised visibility and consistent policy enforcement from day one.
How disruptive is a FortiGate SD-WAN deployment to live operations?
Properly structured, zero disruption. Our methodology is staged: assess and document the current environment first, design the target architecture, then deploy in controlled phases with rollback capability at each step. The most common disruption risk is undocumented existing configuration. The assessment phase surfaces those gaps before any changes are made.
How disruptive is cutover for live branch operations?
Cutover is the highest-risk moment in a live SD-WAN migration, so it is planned before any change window opens. FortiGate SD-WAN is deployed in parallel with the existing environment first. Each site is validated against agreed application, failover and security baselines before production traffic is moved. Rollback is defined before the change window, and after-hours cutover is standard for production sites. Most branches experience no user impact when the work is staged properly. Cutover is typically completed in under an hour per site, subject to site complexity, underlay readiness and existing configuration quality.
How does zero-touch provisioning work with Fortinet?
Hardware ships from the manufacturer pre-registered to your FortiManager instance. When a device powers on at a branch site, it connects to FortiManager over the internet, authenticates and downloads its full configuration automatically. No pre-configuration by a technician on site. The branch joins the SD-WAN fabric within minutes of being powered on. This is what makes 110+ site deployments in under 60 days operationally possible.
What is FortiSASE and do we need it now?
FortiSASE adds cloud-delivered ZTNA, secure web gateway and CASB to the SD-WAN foundation. FortiGate supports SASE features under FortiOS, which means they can be activated on existing hardware when security requirements mature. SASE is not required on day one, but the Fortinet architecture does not require a hardware refresh to get there. The upgrade path is built in from the start.
How much does Fortinet SD-WAN cost?
Indicative range: typically in the range of $300 to $800 per site per month for smaller multi-site deployments, including hardware, licensing and managed service. Larger distributed deployments of 50 or more sites typically start from $150 per site per month with volume pricing. Actual cost is subject to site count, underlay options, FortiGate hardware sizing, FortiGuard subscription bundle and managed service scope. The relevant comparison is total cost against current MPLS circuit spend plus internal IT overhead. A site audit is completed before any commercial proposal so the estimate reflects the actual Fortinet environment.
Can Fortinet SD-WAN work with our existing links?
Yes. Fortinet SD-WAN can work with existing NBN, fibre, broadband, 4G/5G, Starlink and MPLS links. The review identifies the best underlay mix per site. Existing connections do not need to be replaced before the architecture is understood.
What happens if we exit VeloCloud or another SD-WAN platform?
Organisations exiting VMware VeloCloud following the Broadcom acquisition often need an SD-WAN redesign without disrupting live operations. We provide migration assessment, FortiGate SD-WAN architecture redesign and staged cutover planning. The previous environment continues to operate during the transition. Rollback procedures are defined before every change window. MPLS or legacy SD-WAN is decommissioned at each site only after the FortiGate environment has been stable under production load.