Branch Router for Remote Work and SD-WAN
The Branch Router in 2026: More Than Just a Router
The days when a branch received a basic Cisco 881 router connected to headquarters through an IPsec VPN are over. In 2026, a modern branch requires SD-WAN (multi-link aggregation combining fiber and 4G/5G), a local NGFW (the headquarters appliance no longer protects direct Internet traffic), ZTNA for remote workers (replacing legacy VPN), and integrated Wi-Fi or a PoE switch for local equipment. All of this must fit into a compact appliance (1U rackmount or desktop) that supports zero-touch deployment.
The role of this router is to consolidate connectivity, security, and management at a single point. It is the branch's SASE edge.
The Three Leading Branch Platforms
FortiGate 40F / 60F: The Price-to-Feature Champion
For 80% of branches with fewer than 50 employees in France, the FortiGate 60F is the right choice. It provides a complete NGFW, integrated SD-WAN without an additional license, unlimited IPsec/SSL VPN, and 5-7 GbE LAN switch ports. One appliance, one invoice.
- FortiGate 40F (FG-40F): 5 Gbps FW / 600 Mbps Threat. 5 GbE ports. For branches with 5-20 employees. OPTINOC price: ~€450 excluding tax. 1-year UTP license: ~€350.
- FortiGate 60F (FG-60F): 10 Gbps FW / 700 Mbps Threat. 7 GbE ports + 2 SFP. For branches with 20-50 employees. Price: ~€700 excluding tax. UTP license: ~€550/year.
- FortiGate 60F-3G4G: version with an integrated 4G/LTE modem (SIM slot). For branches without reliable fiber connectivity. Price: ~€900 excluding tax.
- Integrated SD-WAN: dual-WAN (fiber + 4G or 2 fiber links), application-aware path selection (Office 365 routed over the best link, priority for critical ERP traffic), FEC, and packet duplication for voice/video.
Cisco Meraki MX67 / MX68: Cloud-Managed Zero-Touch Deployment
The Meraki MX range is specifically designed for cloud-managed multi-branch deployments. The branch manager only sees an appliance that configures itself—all management is performed from the Meraki dashboard at headquarters.
- Meraki MX67: 450 Mbps FW / 300 Mbps Threat. 5 GbE ports. For up to 50 users. OPTINOC price: ~€550 excluding tax. Mandatory Enterprise license: ~€450/year.
- Meraki MX67W: version with integrated Wi-Fi 6. Price: ~€650 excluding tax.
- Meraki MX68: 500 Mbps FW / 350 Mbps Threat. 12 GbE ports (8 PoE+). For larger branches or deployments with Meraki APs. Price: ~€800 excluding tax.
- Meraki Auto VPN: one-click site-to-site VPN configuration through the dashboard. All Meraki sites are automatically connected in a mesh.
- Limitations: no CLI, limited customization, mandatory license (the equipment stops operating if it expires), and basic SD-WAN.
Cisco Catalyst 8200: Viptela SD-WAN for Enterprise Branches
For enterprises with an established Cisco SD-WAN (Viptela) strategy, the Catalyst 8200 is the standard branch router. It offers vManage integration, security through Umbrella (DNS) or Firepower (local NGFW), and modern IOS-XE.
- Catalyst 8200-1N-4T (C8200-1N-4T): 250 Mbps SD-WAN. 5 GbE ports. For branches with 10-50 users. OPTINOC price: ~€3,000 excluding tax.
- Catalyst 8200L: version with an integrated Cat6 LTE modem. Price: ~€3,500 excluding tax.
- License: Network Essentials (NE) or Network Advantage (NA). €100-400/site/year.
- Requires centralized vManage + vBond + vSmart orchestration. Complex for deployments with fewer than 50 sites.
Standard Configuration for a 30-Person Branch
Scenario: a 30-person bank branch with 500 Mbps fiber + 4G failover + 5 remote workers.
FortiGate 60F Option (Recommended)
- WAN1: 500 Mbps SFR fiber → wan1 interface.
- WAN2: Huawei 4G USB dongle → wan2 interface.
- LAN: internal 5-port switch → VLAN 10 (office network, DHCP 10.0.10.0/24) + VLAN 20 (employee Wi-Fi) + VLAN 30 (guest Wi-Fi with limited bandwidth).
- SD-WAN: wan1 primary, wan2 backup (failover if latency exceeds 100ms or loss exceeds 2%).
- Site-to-site VPN: IPsec IKEv2 AES-256-GCM tunnel to the FortiGate 200F at headquarters.
- Remote-work SSL VPN: up to 5 users, FortiToken Mobile 2FA, and free FortiClient.
- Security: UTP enabled (IPS, AV, Web Filter, App Control), with logs sent to the central FortiAnalyzer.
- Total budget: FortiGate 60F (€700) + 3-year UTP license (€1,650) = €2,350 excluding tax for 3 years.
Meraki MX67 Option (Cloud Alternative)
- Configuration from the Meraki dashboard at headquarters. No on-site intervention required.
- Auto VPN: the branch connects automatically to the Meraki hub with one click.
- Client VPN: Meraki Client VPN for remote workers (L2TP over IPsec).
- Total budget: MX67 (€550) + 3-year Enterprise license (€1,350) = €1,900 excluding tax.
- Advantage: no on-site technical expertise required.
- Disadvantage: limited Threat throughput (300 Mbps) and less flexibility than a FortiGate.
Integrated or Separate Wi-Fi
- FortiGate 60F + 1 FortiAP 231F (€70 AP + PoE injector): better control, Security Fabric integration, ~€900 total. Suitable for 100m² coverage.
- Meraki MX67W (with integrated Wi-Fi 6): all-in-one, ~€650. Limited to 1 2.4/5 GHz radio (no Wi-Fi 6E).
- FortiGate 60F + 2-3 Aruba Instant On AP22 units (~€200 each): better Wi-Fi coverage for a 100-300m² branch. Total: €1,100-1,300.
Remote Work: VPN vs ZTNA
For a branch's 5-10 remote workers, there are two approaches:
- Traditional SSL VPN: free FortiClient or Cisco AnyConnect. Full tunnel to the branch or headquarters. Simple and functional, but outdated in 2026.
- ZTNA (Zero Trust Network Access): granular application access without a full network tunnel. Fortinet ZTNA (included with FortiOS 7+), Cisco Duo + Secure Access. More secure with a better UX, but more complex to deploy.
- 2026 recommendation: a basic SSL VPN for 5-10 remote workers at an SMB. ZTNA is mandatory for 50+ remote workers or organizations subject to NIS2 requirements.
OPTINOC Recommendations
- SMB branch with 5-50 employees and no technical team: Meraki MX67 + MR APs (cloud-managed).
- SMB branch with 5-50 employees and an in-house technical team: FortiGate 60F + FortiAPs (better TCO).
- Enterprise branch within a Cisco SD-WAN strategy: Catalyst 8200 + Viptela.
- Branch requiring 4G failover: FortiGate 60F-3G4G or MX67 + 4G dongle.
OPTINOC supplies all three platforms with the manufacturer's warranty and optional initial configuration (pre-cabled and tested before shipment). Delivery to branches across Europe within 24-72h.
