Designing an SD-WAN Architecture
Designing an SD-WAN architecture requires careful consideration of WAN links, sites, critical applications, and security. SD-WAN will replace MPLS in 60% of use cases by 2027 (Gartner). A step-by-step architecture guide covering planning, topology, sizing, and vendors. 2026.
Step 1: Site inventory
- Number of sites (HQ, branches, data centers, remote workers)
- Classification: hub (HQ/DC), spoke (branches), teleworker
- Bandwidth per site (current + projected)
- Criticality: 24/7, 8×5, backup only
Step 2: WAN link inventory
- Current MPLS services (contracts, cost €/Mbps, expiration)
- Internet ADSL/FTTH/4G/5G connectivity by site
- Carrier contracts (SLA, commitment)
- Redundancy requirements (at least 2 links per critical site)
Step 3: Applications and SLAs
- Voice/Video: latency <150ms, jitter <30ms, loss <1%
- ERP/CRM (Salesforce, SAP): latency <200ms, throughput 1-10 Mbps per user
- SaaS (Office 365, Google Workspace): cloud on-ramp preferred
- Backup/replication: off-peak, low priority
Step 4: Topology
Hub-and-spoke (traditional)
All sites connect to the HQ. Advantage: centralized control. Disadvantage: inter-spoke traffic passes through the HQ, which is inefficient for site-to-site VoIP.
Full mesh
IPsec tunnels between all sites. This creates a scalability issue (100 sites = 4950 tunnels). The solution is ADVPN/Auto-VPN, which creates tunnels dynamically.
Hybrid (recommended)
Hub-and-spoke for centralized traffic plus dynamic full mesh for inter-spoke traffic (VoIP, video). This is the model used by most modern SD-WAN solutions.
Step 5: Solution selection
- FortiGate SD-WAN: native FortiOS SD-WAN with no separate license, recommended for <500 sites
- Cisco SD-WAN (Viptela): enterprise market leader, cloud-based vManage
- VMware VeloCloud: cloud-first, easy to deploy, 100+ sites
- Palo Alto Prisma SD-WAN: native SASE integration
- Versa Networks: hardware-independent, Gartner leader
Step 6: Integrated security
- Firewall on every WAN Edge (stateful at a minimum)
- IPS/URL Filtering at the hub and critical sites
- SSL Decryption for deep inspection
- SASE/SSE integration: Zscaler, Cisco Umbrella, Prisma Access
Step 7: Bandwidth sizing
- Users × 2 Mbps + SaaS × 5 Mbps + VoIP × 100 Kbps + videoconferencing × 3 Mbps + 30% headroom
- Site with 50 users: ~500 Mbps FTTH + 100 Mbps 4G backup
- Hub with 500 users: 2× 1 Gbps FTTH links from different carriers
Step 8: Phased migration
- Pilot across 2-3 sites (1-3 months)
- Rollout in waves (10-20 sites/month)
- MPLS + SD-WAN coexistence during migration (6-12 months)
- Final MPLS decommissioning
3-year TCO comparison for 50 sites
- Traditional MPLS: €15,000/site × 50 = €750,000/year × 3 = €2.25M
- Internet-only SD-WAN: €3,000/site × 50 = €150,000/year × 3 + SD-WAN licenses ~€400,000 = €850,000
- 3-year savings: ~€1.4M
Order from OPTINOC
Complimentary SD-WAN audit. Turnkey FortiGate/Cisco/Palo Alto design and migration. Quote for 10-500 sites within 48 hours.
