Multi-Site Network: WAN Design and Centralization
Designing a multi-site network for headquarters, branch offices, and warehouses requires a robust SD-WAN architecture, consistent security, and centralized management, with a phased replacement of legacy MPLS. Complete 2026 multi-site design guide: topologies, WAN, security, sizing, and TCO.
Site Types
- HQ (Headquarters): 100-500 users, local data center, high-speed internet
- Branch offices: 5-100 users, little or no local IT support
- Secondary data center (DR)
- Remote workers: individual endpoints connected via ZTNA
- Mobile sites: vans and food trucks (4G/5G)
Topologies
Hub-and-Spoke
All spokes connect to the HQ. This architecture is simple and provides centralized inspection, but it increases inter-spoke latency.
Full-Mesh ADVPN
Dynamic on-demand inter-spoke tunnels (FortiGate ADVPN, Cisco DMVPN) provide optimal latency.
Hybrid (2026 Standard)
Hub-and-spoke for outbound internet traffic, with a dynamic full mesh for inter-site VoIP and video.
Multi-Site SD-WAN
- FortiGate SD-WAN: 60F/80F/100F at spokes and 200F/400F at the hub. Native SD-WAN at no additional cost
- Cisco SD-WAN (Viptela): Catalyst 8200 at spokes, 8500 at the hub, and cloud-based vManage
- Meraki MX: cloud-first, easy to deploy, with mandatory licenses
- Palo Alto Prisma SD-WAN: native SASE integration
WAN Connectivity
- Primary link: FTTH 300 Mbps-1 Gbps (carrier A)
- Secondary link: FTTH 100-500 Mbps (different carrier B)
- 4G/5G backup: Teltonika RUTX11 router or FortiExtender
- Critical sites: 3 links (2 fixed links + 4G/5G)
Multi-Site Security
- Consistent firewalls across all sites (using the same vendor is recommended)
- NGFW inspection enabled everywhere (IPS, AV, Web Filter)
- Consistent VLAN segmentation (VLAN 10=data, 20=voice, etc.)
- Centralized policies (FortiManager, Panorama, Meraki Dashboard)
- Centralized AD/Azure AD authentication (RADIUS)
- SASE for remote workers and cloud access
Centralized Management
- FortiManager: 10-10,000 FortiGate devices, with ADOMs by site
- Cisco DNA Center: templates and intent-based networking
- Panorama: Palo Alto templates and device groups
- Meraki Dashboard: simple and cloud-only
Multi-Site Voice Services
- Centralized SIP trunking at the HQ (Teams, 3CX, Asterisk)
- IP phones on the VOICE VLAN with PoE+
- End-to-end DSCP EF QoS
- Backup: emergency DISA access and mobile SIP phones
Typical Sizing for 20 Branch Offices
- HQ: 2× FortiGate 200F in HA + FortiManager + FortiAnalyzer
- 20× FortiGate 60F or 80F devices at spokes
- Switches and APs at each site based on size (5-50 users)
- WAN: FTTH + 4G at each site
- Budget: ~€180,000 excluding tax for hardware + €80,000 for licenses and 3 years of coverage
MPLS → SD-WAN Migration
- Phase 1: pilot at 2-3 sites alongside MPLS (1-3 months)
- Phase 2: rollout in waves (5-10 sites/month)
- Phase 3: MPLS+SDWAN coexistence (6-12 months)
- Phase 4: MPLS decommissioning
- Savings: 40-70% over a 3-year TCO
Order from OPTINOC
Turnkey multi-site design and migration. MPLS → SD-WAN audit. FortiGate/Cisco/Palo Alto/Meraki. Quotes for 10-500 sites within 48 hours.
