SD-WAN with FortiGate: connecting several sites without expensive leased lines
Two ordinary internet links, a FortiGate at each site, and your branches talk to each other with automatic failover. How it works, and who it is for.
28 August 2026 · 1 min read · ALLSAFE SOLUTIONS

For a long time, connecting a head office to its branches meant leasing dedicated lines, expensive and slow to install. SD-WAN changes the equation: several ordinary internet links, fibre or 4G/5G, become a reliable private network thanks to an intelligent appliance at each site.
The principle
A FortiGate firewall at each site builds encrypted tunnels to the other sites over every available internet link. It continuously measures latency, jitter and packet loss on each path, and steers each type of traffic onto the best link at that moment. If a link goes down, failover is automatic and invisible to users.
What it changes day to day
- Voice stays clear: IP telephony is prioritised and pinned to the most stable link.
- The ERP responds: critical applications go before Windows updates and video.
- A carrier outage goes unnoticed: the second link takes over within seconds.
- Remote work is secure: staff connect to the nearest site over VPN.
A trap to know about
SD-WAN spreads traffic across links. Some flows hate that: SIP, SBC tunnels, long-lived connections. Without an explicit rule, a session can switch links mid-stream and drop. We pin those flows to a single link at design time. It is a detail that separates a successful deployment from a painful one.
Who is it for?
Any company with at least two sites, or one site plus remote workers, that depends on telephony or a central ERP. Multi-clinic healthcare groups, service companies with branches, manufacturers with a remote warehouse: this is our most common case.
See our network infrastructure and WiFi service.
Let’s talk about your project.
Free initial audit, reply within one business day.





























