Skip to main content

Branch Router for Remote Work and SD-WAN

·5 min read·955 words

The Branch Router in 2026: More Than Just a Router

The days when a branch received a basic Cisco 881 router connected to headquarters through an IPsec VPN are over. In 2026, a modern branch requires SD-WAN (multi-link aggregation combining fiber and 4G/5G), a local NGFW (the headquarters appliance no longer protects direct Internet traffic), ZTNA for remote workers (replacing legacy VPN), and integrated Wi-Fi or a PoE switch for local equipment. All of this must fit into a compact appliance (1U rackmount or desktop) that supports zero-touch deployment.

The role of this router is to consolidate connectivity, security, and management at a single point. It is the branch's SASE edge.

The Three Leading Branch Platforms

FortiGate 40F / 60F: The Price-to-Feature Champion

For 80% of branches with fewer than 50 employees in France, the FortiGate 60F is the right choice. It provides a complete NGFW, integrated SD-WAN without an additional license, unlimited IPsec/SSL VPN, and 5-7 GbE LAN switch ports. One appliance, one invoice.

  • FortiGate 40F (FG-40F): 5 Gbps FW / 600 Mbps Threat. 5 GbE ports. For branches with 5-20 employees. OPTINOC price: ~€450 excluding tax. 1-year UTP license: ~€350.
  • FortiGate 60F (FG-60F): 10 Gbps FW / 700 Mbps Threat. 7 GbE ports + 2 SFP. For branches with 20-50 employees. Price: ~€700 excluding tax. UTP license: ~€550/year.
  • FortiGate 60F-3G4G: version with an integrated 4G/LTE modem (SIM slot). For branches without reliable fiber connectivity. Price: ~€900 excluding tax.
  • Integrated SD-WAN: dual-WAN (fiber + 4G or 2 fiber links), application-aware path selection (Office 365 routed over the best link, priority for critical ERP traffic), FEC, and packet duplication for voice/video.

Cisco Meraki MX67 / MX68: Cloud-Managed Zero-Touch Deployment

The Meraki MX range is specifically designed for cloud-managed multi-branch deployments. The branch manager only sees an appliance that configures itself—all management is performed from the Meraki dashboard at headquarters.

  • Meraki MX67: 450 Mbps FW / 300 Mbps Threat. 5 GbE ports. For up to 50 users. OPTINOC price: ~€550 excluding tax. Mandatory Enterprise license: ~€450/year.
  • Meraki MX67W: version with integrated Wi-Fi 6. Price: ~€650 excluding tax.
  • Meraki MX68: 500 Mbps FW / 350 Mbps Threat. 12 GbE ports (8 PoE+). For larger branches or deployments with Meraki APs. Price: ~€800 excluding tax.
  • Meraki Auto VPN: one-click site-to-site VPN configuration through the dashboard. All Meraki sites are automatically connected in a mesh.
  • Limitations: no CLI, limited customization, mandatory license (the equipment stops operating if it expires), and basic SD-WAN.

Cisco Catalyst 8200: Viptela SD-WAN for Enterprise Branches

For enterprises with an established Cisco SD-WAN (Viptela) strategy, the Catalyst 8200 is the standard branch router. It offers vManage integration, security through Umbrella (DNS) or Firepower (local NGFW), and modern IOS-XE.

  • Catalyst 8200-1N-4T (C8200-1N-4T): 250 Mbps SD-WAN. 5 GbE ports. For branches with 10-50 users. OPTINOC price: ~€3,000 excluding tax.
  • Catalyst 8200L: version with an integrated Cat6 LTE modem. Price: ~€3,500 excluding tax.
  • License: Network Essentials (NE) or Network Advantage (NA). €100-400/site/year.
  • Requires centralized vManage + vBond + vSmart orchestration. Complex for deployments with fewer than 50 sites.

Standard Configuration for a 30-Person Branch

Scenario: a 30-person bank branch with 500 Mbps fiber + 4G failover + 5 remote workers.

FortiGate 60F Option (Recommended)

  • WAN1: 500 Mbps SFR fiber → wan1 interface.
  • WAN2: Huawei 4G USB dongle → wan2 interface.
  • LAN: internal 5-port switch → VLAN 10 (office network, DHCP 10.0.10.0/24) + VLAN 20 (employee Wi-Fi) + VLAN 30 (guest Wi-Fi with limited bandwidth).
  • SD-WAN: wan1 primary, wan2 backup (failover if latency exceeds 100ms or loss exceeds 2%).
  • Site-to-site VPN: IPsec IKEv2 AES-256-GCM tunnel to the FortiGate 200F at headquarters.
  • Remote-work SSL VPN: up to 5 users, FortiToken Mobile 2FA, and free FortiClient.
  • Security: UTP enabled (IPS, AV, Web Filter, App Control), with logs sent to the central FortiAnalyzer.
  • Total budget: FortiGate 60F (€700) + 3-year UTP license (€1,650) = €2,350 excluding tax for 3 years.

Meraki MX67 Option (Cloud Alternative)

  • Configuration from the Meraki dashboard at headquarters. No on-site intervention required.
  • Auto VPN: the branch connects automatically to the Meraki hub with one click.
  • Client VPN: Meraki Client VPN for remote workers (L2TP over IPsec).
  • Total budget: MX67 (€550) + 3-year Enterprise license (€1,350) = €1,900 excluding tax.
  • Advantage: no on-site technical expertise required.
  • Disadvantage: limited Threat throughput (300 Mbps) and less flexibility than a FortiGate.

Integrated or Separate Wi-Fi

  • FortiGate 60F + 1 FortiAP 231F (€70 AP + PoE injector): better control, Security Fabric integration, ~€900 total. Suitable for 100m² coverage.
  • Meraki MX67W (with integrated Wi-Fi 6): all-in-one, ~€650. Limited to 1 2.4/5 GHz radio (no Wi-Fi 6E).
  • FortiGate 60F + 2-3 Aruba Instant On AP22 units (~€200 each): better Wi-Fi coverage for a 100-300m² branch. Total: €1,100-1,300.

Remote Work: VPN vs ZTNA

For a branch's 5-10 remote workers, there are two approaches:

  • Traditional SSL VPN: free FortiClient or Cisco AnyConnect. Full tunnel to the branch or headquarters. Simple and functional, but outdated in 2026.
  • ZTNA (Zero Trust Network Access): granular application access without a full network tunnel. Fortinet ZTNA (included with FortiOS 7+), Cisco Duo + Secure Access. More secure with a better UX, but more complex to deploy.
  • 2026 recommendation: a basic SSL VPN for 5-10 remote workers at an SMB. ZTNA is mandatory for 50+ remote workers or organizations subject to NIS2 requirements.

OPTINOC Recommendations

  • SMB branch with 5-50 employees and no technical team: Meraki MX67 + MR APs (cloud-managed).
  • SMB branch with 5-50 employees and an in-house technical team: FortiGate 60F + FortiAPs (better TCO).
  • Enterprise branch within a Cisco SD-WAN strategy: Catalyst 8200 + Viptela.
  • Branch requiring 4G failover: FortiGate 60F-3G4G or MX67 + 4G dongle.

OPTINOC supplies all three platforms with the manufacturer's warranty and optional initial configuration (pre-cabled and tested before shipment). Delivery to branches across Europe within 24-72h.

Frequently Asked Questions

Reply within 2 business hours

Need a quote?

Our technical team responds within 2 business hours. European delivery 24-72h.

Request a quote