Skip to main content

Designing an SD-WAN Architecture

·3 min read·417 words

Designing an SD-WAN architecture requires careful consideration of WAN links, sites, critical applications, and security. SD-WAN will replace MPLS in 60% of use cases by 2027 (Gartner). A step-by-step architecture guide covering planning, topology, sizing, and vendors. 2026.

Step 1: Site inventory

  • Number of sites (HQ, branches, data centers, remote workers)
  • Classification: hub (HQ/DC), spoke (branches), teleworker
  • Bandwidth per site (current + projected)
  • Criticality: 24/7, 8×5, backup only

Step 2: WAN link inventory

  • Current MPLS services (contracts, cost €/Mbps, expiration)
  • Internet ADSL/FTTH/4G/5G connectivity by site
  • Carrier contracts (SLA, commitment)
  • Redundancy requirements (at least 2 links per critical site)

Step 3: Applications and SLAs

  • Voice/Video: latency <150ms, jitter <30ms, loss <1%
  • ERP/CRM (Salesforce, SAP): latency <200ms, throughput 1-10 Mbps per user
  • SaaS (Office 365, Google Workspace): cloud on-ramp preferred
  • Backup/replication: off-peak, low priority

Step 4: Topology

Hub-and-spoke (traditional)

All sites connect to the HQ. Advantage: centralized control. Disadvantage: inter-spoke traffic passes through the HQ, which is inefficient for site-to-site VoIP.

Full mesh

IPsec tunnels between all sites. This creates a scalability issue (100 sites = 4950 tunnels). The solution is ADVPN/Auto-VPN, which creates tunnels dynamically.

Hybrid (recommended)

Hub-and-spoke for centralized traffic plus dynamic full mesh for inter-spoke traffic (VoIP, video). This is the model used by most modern SD-WAN solutions.

Step 5: Solution selection

  • FortiGate SD-WAN: native FortiOS SD-WAN with no separate license, recommended for <500 sites
  • Cisco SD-WAN (Viptela): enterprise market leader, cloud-based vManage
  • VMware VeloCloud: cloud-first, easy to deploy, 100+ sites
  • Palo Alto Prisma SD-WAN: native SASE integration
  • Versa Networks: hardware-independent, Gartner leader

Step 6: Integrated security

  • Firewall on every WAN Edge (stateful at a minimum)
  • IPS/URL Filtering at the hub and critical sites
  • SSL Decryption for deep inspection
  • SASE/SSE integration: Zscaler, Cisco Umbrella, Prisma Access

Step 7: Bandwidth sizing

  • Users × 2 Mbps + SaaS × 5 Mbps + VoIP × 100 Kbps + videoconferencing × 3 Mbps + 30% headroom
  • Site with 50 users: ~500 Mbps FTTH + 100 Mbps 4G backup
  • Hub with 500 users: 2× 1 Gbps FTTH links from different carriers

Step 8: Phased migration

  • Pilot across 2-3 sites (1-3 months)
  • Rollout in waves (10-20 sites/month)
  • MPLS + SD-WAN coexistence during migration (6-12 months)
  • Final MPLS decommissioning

3-year TCO comparison for 50 sites

  • Traditional MPLS: €15,000/site × 50 = €750,000/year × 3 = €2.25M
  • Internet-only SD-WAN: €3,000/site × 50 = €150,000/year × 3 + SD-WAN licenses ~€400,000 = €850,000
  • 3-year savings: ~€1.4M

Order from OPTINOC

Complimentary SD-WAN audit. Turnkey FortiGate/Cisco/Palo Alto design and migration. Quote for 10-500 sites within 48 hours.

Frequently Asked Questions

Reply within 2 business hours

Need a quote?

Our technical team responds within 2 business hours. European delivery 24-72h.

Request a quote