What SD-WAN Actually Does

Traditional routing is dumb in a specific way: you configure a route, and traffic follows that route regardless of conditions. If the path is congested, degraded, or flapping, traffic goes that way anyway. The only exception is a manually configured failover — and most businesses only find out it doesn't work properly during an actual outage.

SD-WAN replaces that static approach with intelligent, real-time routing. The SD-WAN device continuously monitors the quality of every available internet connection — measuring latency, jitter, and packet loss every few seconds — and routes traffic based on what's actually performing well right now. It can also route different types of traffic via different paths: send VoIP calls via the low-latency link, bulk file transfers via the cheaper high-bandwidth link, and Microsoft 365 traffic directly to the internet rather than backhauling it through a VPN.

Figure 1 — Traditional routing vs. SD-WAN: how traffic is handled when a link degrades
Traditional RoutingAll traffic → primary route (static)Link A — 50MbpsLink B (unused)Teams call ↑File download ↑Both competing on Link ATeams call degradesSD-WAN (FortiGate)Traffic routed by type + link healthLink A — 50Mbps ✓Link B — 4G ✓Teams callFile downloadlow latency →high bandwidth →Each on the optimal linkTeams call clear ✓

The Five Signs You're Ready for SD-WAN

01
You have two or more offices that need to share data or applications

Traditional multi-site connectivity means an MPLS circuit or a manually configured VPN. MPLS is expensive and inflexible. DIY VPNs work but don't optimise traffic intelligently. SD-WAN connects sites over standard internet connections with automatic failover and traffic optimisation — at a fraction of MPLS cost.

02
Teams calls are unreliable even though your internet speed tests fine

Speed tests measure peak throughput, not latency or jitter. SD-WAN measures these continuously and routes voice/video traffic via the link with the lowest latency and jitter right now — not the link that was best when you manually configured the route six months ago.

03
You've added a second internet connection for redundancy but it's not doing much

A second connection sitting idle until someone manually switches to it isn't redundancy — it's expensive insurance you'll probably miss when you need it. SD-WAN puts both connections to work simultaneously and switches automatically in seconds when one degrades.

04
Your staff VPN performance is poor

Legacy VPN setups route all remote-worker traffic through a central hub before it reaches the internet — including Microsoft 365 traffic, which means it goes from the remote worker's home → your office → Microsoft → back to your office → back to the worker. SD-WAN with split tunnelling sends M365 traffic directly to Microsoft and only routes internal traffic through the VPN.

05
You're planning to open a second or third site in the next 12 months

Designing SD-WAN into a network from the start is significantly easier than retrofitting it later. If growth is on the horizon, building on FortiGate with SD-WAN capability now means adding a site later is a configuration exercise, not a hardware replacement project.

SD-WAN on FortiGate: How It Works in Practice

On a FortiGate, SD-WAN is not a separate product or appliance — it's a feature of the firewall operating system. This matters because it means you don't need extra hardware, extra management consoles, or extra vendor relationships. The same device that does your firewall, IPS, VPN, and QoS also handles SD-WAN.

Figure 2 — FortiGate SD-WAN: multi-site connectivity with per-application path selection
Microsoft 365Melbourne Head OfficeFortiGate 100F · SD-WAN · NBN + 4GM365 directBranch — DandenongFortiGate 60F · NBN + 4GBranch — SunshineFortiGate 60F · NBN + 5GIPsec SD-WAN overlayIPsec SD-WAN overlaySD-WAN overlay (internal traffic)M365 direct breakout (each site)Managed via FortiManager

Key FortiGate SD-WAN features that matter for Melbourne SMBs:

  • Application-aware routing: FortiGate recognises over 5,000 applications by signature. You can tell it to send Teams calls via Link A if latency is below 50ms, switch to Link B if it rises above that threshold, and never send Teams traffic through a proxy.
  • SLA-based failover: Define acceptable thresholds for latency, jitter and packet loss. If a link breaches any threshold, traffic automatically moves to the next best option — no manual intervention.
  • Direct internet breakout: Each site can send Microsoft 365 traffic directly to Microsoft's nearest Point of Presence rather than backhauling it to the head office first. This alone can reduce Teams call latency by 50ms or more for branch users.
  • Central management: All sites managed from FortiManager. Push a new SD-WAN rule to all sites simultaneously — consistent policy, no manual per-site configuration.

What SD-WAN Costs — and What It Saves

ScenarioWithout SD-WANWith SD-WAN (FortiGate)
Multi-site connectivityMPLS: $500–2,000+/month per siteStandard NBN + SD-WAN overlay: $80–200/month per site
Internet failoverManual switchover, minutes to hours of downtimeAutomatic, 30–60 seconds, no intervention
Teams/VoIP qualityDegrades when link is congestedPriority routing maintains call quality under load
Remote worker VPNAll traffic via hub — slow M365 accessSplit tunnel: M365 direct, internal via VPN

The SD-WAN licence on a FortiGate is included in the standard FortiGuard bundle — there's no separate SD-WAN subscription. If you're already running a FortiGate with active licensing, SD-WAN is available to enable and configure. This is one of the reasons we standardise on FortiGate: the capability is there when the business needs it, without a hardware refresh.

💡
SD-WAN is not just for multi-site businesses
Even a single-site business with two internet connections (NBN primary + 4G failover) benefits from SD-WAN. Without it, the failover connection sits idle until someone notices the primary is down and manually switches. With SD-WAN, both links are active, quality is monitored continuously, and failover happens automatically.

When You Probably Don't Need SD-WAN Yet

SD-WAN solves specific problems. If you don't have those problems, you don't need to pay for the solution:

  • Single site, single internet connection, and you're not planning to add redundancy
  • Fewer than 15 staff with basic Microsoft 365 usage — email and simple file sharing — and Teams calls are occasional rather than constant
  • No branch offices and no plans to open them

In these scenarios, a well-configured FortiGate with QoS policies will address most performance issues without needing full SD-WAN. You can always enable it later — the hardware and licensing support it — when the business needs evolve.

The Bottom Line

SD-WAN is worth serious consideration if you have multiple sites, rely heavily on Teams calls, or have two internet connections that aren't both earning their keep. On FortiGate hardware, it's a configuration change rather than a new platform — which makes the barrier to entry much lower than the "enterprise" label suggests.

If you're not sure whether your current setup would benefit from SD-WAN, we can run a network assessment and show you exactly what your links are doing — and where intelligent routing would make a measurable difference.