The SD-WAN Rollout Problem
You're managing five retail locations, a warehouse, and two office buildings across Southern California. Internet circuits at each site are inconsistent. Branch firewalls are outdated. Management wants faster provisioning and lower WAN costs.
SD-WAN looks like the answer. One cloud-based controller, policy-driven routing, automatic failover to LTE. Roll it out, forget about branch hardware, save money.
Then your security team asks: what happens when a compromised POS terminal at Site 3 tries to reach the data center? Or when a camera on the guest network accidentally gets routed through the main tunnel? Or when a branch office gets breached and you realize you have no visibility into what traffic actually crossed the SD-WAN overlay?
SD-WAN is transport. It's not a firewall. It's not segmentation. It's not zero trust. If you treat it like it is, you've just made your multi-site attack surface harder to defend.
What SD-WAN Actually Does (and Doesn't)
SD-WAN controllers manage application routing, link quality, and failover. They're good at that. They handle IPSec tunnels back to a hub (or mesh between sites). They optimize bandwidth. They reduce hardware costs at branches.
What they don't do:
- Inspect application layer traffic between branches
- Enforce zero trust policies based on user identity or device posture
- Segment IoT devices (cameras, access control panels, printers) from office networks
- Prevent lateral movement if one branch is compromised
- Give you granular logging of who accessed what across sites
Most SD-WAN deployments still rely on a hub-and-spoke model where branch traffic tunnels back to a central site, then exits through a next-generation firewall (NGFW) or Secure Web Gateway (SWG). That's good. But if you're running 10 branches, you're either funneling all traffic through one bottleneck or you're letting branch-to-branch traffic bypass inspection entirely.
How to Design SD-WAN with Network Segmentation
Start with your physical security and IoT devices. These are the most exposed endpoints on a multi-site network.
Step 1: Segment Before You Deploy SD-WAN
Before you touch the SD-WAN controller, map your VLANs at each branch. This doesn't change when SD-WAN arrives, but it becomes critical.
At a typical retail site, you need:
- VLAN 10: Office (PCs, printers, phones)
- VLAN 20: Guest WiFi (isolated, no access to internal resources)
- VLAN 30: Cameras and access control (PoE-powered, needs controlled outbound only)
- VLAN 40: POS terminals (if separate from office, which they should be)
- VLAN 50: Management network (switches, wireless controllers, UPS, building systems)
Each VLAN gets a firewall rule set that defines what can talk to what. Camera VLAN can reach the on-prem NVR or cloud VMS platform. That's it. No access to file servers, no access to office PCs, no lateral movement.
When SD-WAN comes in, these VLANs stay intact. The SD-WAN tunnel is just another uplink path. The firewall still enforces segmentation.
Step 2: Place Your NGFW at the Right Boundary
In a hub-and-spoke SD-WAN model, the NGFW sits at the hub (usually your main office or a cloud-hosted security appliance). All branch traffic tunnels back, the NGFW inspects it, and policy applies uniformly.
This works if your NGFW can handle the throughput. If you have 10 branches each pushing 50 Mbps, that's 500 Mbps of aggregate traffic. A Fortinet FortiGate 2000F or Palo Alto PA-5220 can handle that. A smaller box can't. Budget for it.
Alternative: deploy a smaller NGFW at each major branch (retail cluster, regional office) and create inspection zones. The regional NGFW inspects local traffic; the hub NGFW inspects inter-region traffic. More complexity, but better performance if you have geographic clusters.
Step 3: Define Zero Trust Policies Across the SD-WAN
Zero trust doesn't mean "block everything." It means verify identity and device posture before granting access, even between sites.
Example rules:
- User in Branch 1 needs to access a file share in the data center. Their device must be registered, patched, and running endpoint protection. If yes, grant access to that specific share. If no, block or require MFA.
- Camera in Branch 2 needs to send video to the cloud platform. Firewall rule allows HTTPS outbound to that platform only. No SSH, no HTTP, no DNS lookups to random IPs.
- Retail manager in Branch 3 needs to access the POS reporting system in the data center. Their traffic goes through an identity-aware proxy. They authenticate with SSO. Access is logged.
SD-WAN controllers can't enforce this. Your NGFW does. Your identity provider (Okta, Entra ID, Ping) does. Your endpoints (with EDR agents) do.
The SD-WAN just moves the traffic. The security stack validates it.
Practical Multi-Site Checklist
Before You Deploy
- Map all VLANs and IP ranges at each branch. Document VLAN 10-50 purpose, DHCP scope, static IPs for IoT
- Audit what devices exist at each branch (how many cameras? Access control panels? Printers? Guests?)
- Determine hub location (main office, cloud-hosted, or regional hub per cluster)
- Size your hub NGFW for peak multi-site throughput. Add 40% headroom
- Confirm WAN circuits at each branch can support SD-WAN (minimum 10 Mbps primary, 5 Mbps secondary)
- List applications that need inter-site access (file shares, databases, VMS, POS reporting, VoIP)
During Deployment
- Set up SD-WAN controller (Cisco Catalyst SD-WAN, Fortinet SD-WAN, Velocloud, etc.)
- Configure hub NGFW with VLAN inspection rules (allow camera VLAN only to VMS, block camera VLAN from office VLAN)
- Test branch-to-hub connectivity. Verify tunnel comes up, traffic passes
- Enable logging on all firewall policies. You need visibility
- Configure failover WAN link (LTE, secondary ISP). Test failover
- Integrate SD-WAN controller with your identity provider so user-based policies can apply
After Deployment
- Monitor hub NGFW CPU and memory weekly for first month. If utilization exceeds 70%, you're close to saturation
- Review firewall logs for blocked traffic. Tune rules if legitimate traffic is being dropped
- Audit VLAN isolation monthly. Verify cameras can't reach office PCs, guests can't reach internal systems
- Test disaster recovery. If hub NGFW fails, do branches still have connectivity? (They should, via secondary ISP or mesh)
Common Mistakes That Bite You Later
Mistake 1: Branch-to-branch traffic bypasses the hub NGFW. Some SD-WAN solutions offer direct branch-to-branch tunnels to reduce latency. This is fine for video traffic between two retail sites. It's terrible if a compromised POS at Site A can talk directly to a POS at Site B without inspection. Disable mesh mode unless you have a specific use case.
Mistake 2: No visibility into SD-WAN tunnels. The SD-WAN controller shows you link quality and throughput. It doesn't show you what applications are running. Your NGFW does. Enable NetFlow or sFlow from your NGFW back to a SIEM or network analytics tool. You need to know if your cameras are suddenly exfiltrating data.
Mistake 3: Assuming SD-WAN replaces a firewall. It doesn't. SD-WAN is routing. Firewalls are policy enforcement. Deploy both.
Mistake 4: Not segmenting IoT before SD-WAN. If your cameras sit on the same VLAN as office PCs, adding SD-WAN doesn't fix that. You still have a flat network at each branch. Segment first, then add SD-WAN.
Mistake 5: Forgetting about remote branches. You have 15 small retail locations that only need basic connectivity (POS, WiFi, camera). They don't warrant a full NGFW deployment. Instead, deploy a lightweight SD-WAN edge device with built-in firewall rules and VLAN support. Fortinet FortiGate 60E, Cisco ISR 1000, Juniper SRX345 can all do this.
Real-World Throughput Example
You have five retail locations. Each location has:
- 20 office users (1 Mbps average per user during business hours)
- 4 IP cameras (3 Mbps each, 12 Mbps aggregate)
- 2 access control panels (minimal bandwidth)
- 1 POS terminal (0.5 Mbps)
- Guest WiFi (separate, not counted)
Peak load per site: 20 + 12 + 0.5 = 32.5 Mbps. Across five sites: 162.5 Mbps.
If all that traffic tunnels through your hub NGFW, you need a box that can handle 200+ Mbps of throughput with full inspection enabled (IPS, DLP, threat prevention). Fortinet FortiGate 2000F does ~4 Gbps throughput but that's without full threat inspection. With inspection, real-world is 400-600 Mbps. You're in range.
If you go cheaper (FortiGate 400F, ~200 Mbps with inspection), you'll hit saturation during peak hours. Traffic gets queued, latency spikes, POS terminals time out.
Budget correctly upfront.
Wrapping Up
SD-WAN is a good tool for multi-site connectivity. It's not a security tool. Pair it with proper VLAN segmentation, a sized NGFW at the hub, and zero trust identity policies. Monitor it. Test failover. Your multi-site network becomes faster, cheaper, and actually defensible.
Need help sizing an NGFW or designing VLANs for your branch locations? Get in touch.