What SD-WAN Actually Does
Traditional routing is dumb in a specific way: you configure a route, and traffic follows that route regardless of conditions. If the path is congested, degraded, or flapping, traffic goes that way anyway. The only exception is a manually configured failover — and most businesses only find out it doesn't work properly during an actual outage.
SD-WAN replaces that static approach with intelligent, real-time routing. The SD-WAN device continuously monitors the quality of every available internet connection — measuring latency, jitter, and packet loss every few seconds — and routes traffic based on what's actually performing well right now. It can also route different types of traffic via different paths: send VoIP calls via the low-latency link, bulk file transfers via the cheaper high-bandwidth link, and Microsoft 365 traffic directly to the internet rather than backhauling it through a VPN.
The Five Signs You're Ready for SD-WAN
Traditional multi-site connectivity means an MPLS circuit or a manually configured VPN. MPLS is expensive and inflexible. DIY VPNs work but don't optimise traffic intelligently. SD-WAN connects sites over standard internet connections with automatic failover and traffic optimisation — at a fraction of MPLS cost.
Speed tests measure peak throughput, not latency or jitter. SD-WAN measures these continuously and routes voice/video traffic via the link with the lowest latency and jitter right now — not the link that was best when you manually configured the route six months ago.
A second connection sitting idle until someone manually switches to it isn't redundancy — it's expensive insurance you'll probably miss when you need it. SD-WAN puts both connections to work simultaneously and switches automatically in seconds when one degrades.
Legacy VPN setups route all remote-worker traffic through a central hub before it reaches the internet — including Microsoft 365 traffic, which means it goes from the remote worker's home → your office → Microsoft → back to your office → back to the worker. SD-WAN with split tunnelling sends M365 traffic directly to Microsoft and only routes internal traffic through the VPN.
Designing SD-WAN into a network from the start is significantly easier than retrofitting it later. If growth is on the horizon, building on FortiGate with SD-WAN capability now means adding a site later is a configuration exercise, not a hardware replacement project.
SD-WAN on FortiGate: How It Works in Practice
On a FortiGate, SD-WAN is not a separate product or appliance — it's a feature of the firewall operating system. This matters because it means you don't need extra hardware, extra management consoles, or extra vendor relationships. The same device that does your firewall, IPS, VPN, and QoS also handles SD-WAN.
Key FortiGate SD-WAN features that matter for Melbourne SMBs:
- Application-aware routing: FortiGate recognises over 5,000 applications by signature. You can tell it to send Teams calls via Link A if latency is below 50ms, switch to Link B if it rises above that threshold, and never send Teams traffic through a proxy.
- SLA-based failover: Define acceptable thresholds for latency, jitter and packet loss. If a link breaches any threshold, traffic automatically moves to the next best option — no manual intervention.
- Direct internet breakout: Each site can send Microsoft 365 traffic directly to Microsoft's nearest Point of Presence rather than backhauling it to the head office first. This alone can reduce Teams call latency by 50ms or more for branch users.
- Central management: All sites managed from FortiManager. Push a new SD-WAN rule to all sites simultaneously — consistent policy, no manual per-site configuration.
What SD-WAN Costs — and What It Saves
| Scenario | Without SD-WAN | With SD-WAN (FortiGate) |
|---|---|---|
| Multi-site connectivity | MPLS: $500–2,000+/month per site | Standard NBN + SD-WAN overlay: $80–200/month per site |
| Internet failover | Manual switchover, minutes to hours of downtime | Automatic, 30–60 seconds, no intervention |
| Teams/VoIP quality | Degrades when link is congested | Priority routing maintains call quality under load |
| Remote worker VPN | All traffic via hub — slow M365 access | Split tunnel: M365 direct, internal via VPN |
The SD-WAN licence on a FortiGate is included in the standard FortiGuard bundle — there's no separate SD-WAN subscription. If you're already running a FortiGate with active licensing, SD-WAN is available to enable and configure. This is one of the reasons we standardise on FortiGate: the capability is there when the business needs it, without a hardware refresh.
Even a single-site business with two internet connections (NBN primary + 4G failover) benefits from SD-WAN. Without it, the failover connection sits idle until someone notices the primary is down and manually switches. With SD-WAN, both links are active, quality is monitored continuously, and failover happens automatically.
When You Probably Don't Need SD-WAN Yet
SD-WAN solves specific problems. If you don't have those problems, you don't need to pay for the solution:
- Single site, single internet connection, and you're not planning to add redundancy
- Fewer than 15 staff with basic Microsoft 365 usage — email and simple file sharing — and Teams calls are occasional rather than constant
- No branch offices and no plans to open them
In these scenarios, a well-configured FortiGate with QoS policies will address most performance issues without needing full SD-WAN. You can always enable it later — the hardware and licensing support it — when the business needs evolve.
The Bottom Line
SD-WAN is worth serious consideration if you have multiple sites, rely heavily on Teams calls, or have two internet connections that aren't both earning their keep. On FortiGate hardware, it's a configuration change rather than a new platform — which makes the barrier to entry much lower than the "enterprise" label suggests.
If you're not sure whether your current setup would benefit from SD-WAN, we can run a network assessment and show you exactly what your links are doing — and where intelligent routing would make a measurable difference.