FortiGate Secure SD-WAN in Dubai, UAE
FortiGate Secure SD-WAN brings application-aware WAN control, advanced routing and FortiGate security functions into a common FortiOS-based platform. For businesses with several branches, cloud applications, hybrid connectivity or changing traffic patterns, the value is not simply replacing one router with another. The practical goal is to create a WAN architecture that can evaluate link health, steer important applications according to business policy and apply security at the branch edge without forcing every session through a distant data centre.
Start with the network requirement
A useful quotation starts with branch count, internet and private circuits, expected inspection load, critical applications, current firewall estate, cloud destinations and the management model. FourTeck can help turn those inputs into a practical FortiGate and service plan.
Networking and security policies share the FortiGate operating environment.
Path decisions can use link health and SD-WAN rules.
Sizing, subscriptions and central management vary by design.
Confirm current model, license, quantity and project scope before ordering.
What should a buyer understand first?
FortiGate Secure SD-WAN is Fortinet’s approach to combining software-defined WAN control with FortiGate firewall, routing and security capabilities. It is mainly used to connect branches, headquarters, data centres, internet services and cloud applications across multiple WAN transports while applying policy-based path selection. Organisations considering it should have more than one site, a need for resilient or application-aware connectivity, or a requirement to consolidate branch networking and security. Before proceeding, confirm the exact FortiGate platform for each location, bandwidth and security-inspection targets, WAN underlays, overlay design, cloud and SaaS dependencies, redundancy needs, FortiGuard and FortiCare choices, central management requirements and migration scope. SD-WAN functionality is built into FortiGate, but some monitoring, cloud, SASE, support and service-bundle capabilities are separately dependent on subscription or chosen architecture.
What it does
SD-WAN lets the FortiGate treat multiple WAN interfaces as members of a policy-controlled connectivity fabric. Administrators can define health checks and performance targets, then use SD-WAN rules to influence which link is preferred for a given traffic class. This is useful when an organisation combines broadband, leased connectivity, MPLS, 4G or 5G, or other supported underlays and wants application traffic to follow paths that meet business objectives rather than a single static default route. The firewall remains responsible for enforcing the configured security policy, so routing decisions and edge security can be considered together instead of being managed as unrelated devices.
Who it suits
Typical candidates include multi-branch companies, retail and hospitality groups, clinics, schools, logistics operations, warehouses, professional offices, distributed service organisations and enterprises moving more workloads to SaaS or public cloud. It is also relevant when an existing WAN depends heavily on backhauling traffic to a central site, when separate branch routers and firewalls create operational complexity, or when network teams want common policy and visibility across many FortiGate edges. It is not automatically the right answer for every site: a single small office with one internet circuit and no branch or application-routing requirement may gain little from a complex overlay design.
Business problems the design can help address
The strongest SD-WAN business case normally starts with an operational problem, not a feature list. The following examples show how the platform can be applied when the underlying network, licenses and policies are designed correctly.
Unpredictable application paths
Static routing may continue using a path even when latency, jitter or loss has deteriorated. FortiGate performance SLA checks can measure link health, and SD-WAN rules can use those results to influence path selection. The thresholds and probe design must reflect the application and network rather than relying on generic values.
Too much branch backhaul
Cloud and SaaS traffic may not need to travel through a headquarters firewall when the branch can securely inspect and route the session locally. A direct-internet-access approach can reduce unnecessary hair-pinning, but it increases the importance of correct branch security policies, DNS design, identity controls, logging and subscription services.
Mixed WAN costs and capabilities
Businesses often have a combination of private links and internet circuits. SD-WAN can use these paths according to performance and policy rather than treating an expensive circuit as the only acceptable transport. Commercial savings are not guaranteed; circuit contracts, quality and application requirements still determine the real outcome.
Distributed policy administration
As branch count grows, individually administered firewalls can become difficult to standardise. FortiManager can provide central management and SD-WAN operational views. Whether it is required depends on scale, existing tools, administrator workflow and the level of orchestration expected.
Core capabilities to evaluate
SD-WAN service rules can match traffic and steer sessions according to defined strategy and policy.
Health checks can evaluate latency, jitter and packet-loss thresholds for SD-WAN members.
WAN decisions operate on the FortiGate, where firewall and subscribed security services can also be applied.
VPN overlays and Fortinet ADVPN designs can support branch-to-hub and dynamic spoke connectivity where appropriate.
FortiManager can help standardise configuration, monitoring, provisioning and policy workflows at scale.
The architecture can be extended toward cloud access and Fortinet SASE options, with licensing and design confirmed separately.
Is FortiGate Secure SD-WAN a good fit?
| Requirement | Suitable when | Confirm before ordering |
|---|---|---|
| Branch resilience | Sites have two or more usable transports and need policy-based failover or path preference. | Circuit diversity, handoff type, IP addressing, failover behaviour and application tolerance. |
| SaaS and cloud access | Users depend on Microsoft 365, collaboration tools, hosted applications or public cloud workloads. | Security inspection, local breakout policy, DNS, identity, logging and cloud routing. |
| Large branch estate | Templates, common policy and central operations are more practical than device-by-device administration. | FortiManager architecture, administrative domains, change process, licensing and operational ownership. |
| MPLS transition | The organisation wants to introduce broadband or internet paths without an immediate all-or-nothing WAN replacement. | Contract dates, routing policy, critical traffic, security design and staged migration plan. |
| Single small site | Basic SD-WAN features may still be useful if multiple links exist, but a complex overlay may be unnecessary. | Business value, admin capability, number of WAN links and whether simple redundancy is sufficient. |
Buyer information and verified platform guidance
| Topic | FortiGate Secure SD-WAN |
|---|---|
| Main purpose | Policy-driven WAN connectivity with integrated FortiGate routing and security. |
| Base SD-WAN availability | Fortinet documentation states that SD-WAN can be enabled on FortiGate without a separate SD-WAN feature license. |
| Operating platform | FortiOS; supported capabilities and limits depend on the FortiGate model and software release. |
| WAN path health | Performance SLA functions can measure link quality and use thresholds such as latency, jitter and packet loss in routing decisions. |
| Overlay options | VPN overlays and ADVPN can be used in suitable designs; topology and release support must be confirmed. |
| Central management | FortiManager can provide central deployment, configuration, SD-WAN monitoring and operational workflows. It is not universally mandatory for every deployment. |
| Security services | FortiGuard subscriptions and service bundles are subscription dependent and should be selected according to required inspection and support functions. |
| SD-WAN service bundles | Current Fortinet ordering guidance includes bundle and add-on choices with different inclusions; exact SKU selection is model and entitlement dependent. |
| FortiCare | Support inclusion varies by bundle or add-on. Confirm the required support entitlement and term. |
| SASE integration | Fortinet positions Secure SD-WAN as a foundation that can integrate with FortiSASE; user licensing and service scope are dependent on the selected offer. |
| Hardware performance | Model dependent. Choose a FortiGate using inspected throughput, interfaces, VPN, session load, branch size and growth rather than firewall throughput alone. |
| UAE availability | Contact FourTeck for current model, license, quantity, lead-time and project-scope confirmation. |
Licensing, service and compatibility dependencies
A common purchasing mistake is assuming that the phrase “SD-WAN included” means every Fortinet service associated with an SD-WAN project is included at no extra cost. Fortinet documentation distinguishes the base SD-WAN functionality from optional subscriptions and service offerings. The base FortiGate can create SD-WAN members, rules and health checks, while advanced monitoring databases, cloud services, FortiGuard security subscriptions, FortiCare support, FortiManager deployments, FortiSASE seats and specific SD-WAN service bundles follow their own entitlement rules. Current ordering guidance should therefore be checked against the exact FortiGate model, software release and commercial bundle being quoted.
Compatibility also includes the existing network. A migration may have to preserve BGP or OSPF routing, VLAN segmentation, VPN peers, DHCP or DNS behaviour, public IP services, inbound NAT, voice traffic, payment applications, CCTV networks and cloud tunnels. Internet circuits from two providers are useful only if their handoffs, addressing and physical paths create the resilience the business expects. Where 4G or 5G is part of the design, modem, FortiExtender, carrier, antenna and coverage requirements should be confirmed separately. High availability at a headquarters or data-centre hub introduces additional appliance, switching, routing and failover considerations. FourTeck can help collect these dependencies before the bill of materials is finalised.
A practical purchase and deployment journey
Map sites and applications
Document branches, users, WAN circuits, private links, SaaS services, cloud workloads, voice, video, business systems and critical traffic flows. This becomes the basis for deciding where local breakout, overlays and special steering policies are useful.
Size each FortiGate role
A small branch, regional hub and data-centre edge may need different models. Size for inspected traffic, VPN, interfaces, sessions, routing and growth. Do not copy one model across all locations purely for administrative convenience.
Define the commercial bundle
Confirm whether the quotation is hardware-only, a security bundle, an SD-WAN services bundle, an add-on, FortiCare support, FortiManager licensing, cloud services or a combination. Terms and inclusions should be explicit.
Design underlay and overlay
Choose which circuits are SD-WAN members, how health will be measured, whether site-to-site VPN or ADVPN is needed, and how hubs, spokes and cloud networks should exchange routes.
Pilot and validate
Test important applications, failover, path recovery, security inspection, voice quality, DNS, inbound services and reporting. A pilot is especially useful when the business is replacing MPLS behaviour or changing where internet security is enforced.
Roll out with operations in mind
Use templates, naming conventions, change control, backups, monitoring and administrator handover. The design should be supportable after go-live, not only technically correct on installation day.
Application steering should reflect business importance
Application-aware path control is one of the most useful reasons to consider Secure SD-WAN, but it requires thoughtful policy. A voice or video service may be sensitive to latency, jitter and packet loss. A software update or cloud backup may tolerate a slower path but consume considerable bandwidth. An internal ERP session may need predictable reachability to a private data centre. A SaaS application may perform better with local internet access rather than a long route through headquarters. FortiGate SD-WAN rules allow administrators to classify traffic and choose a strategy, while performance SLA checks provide information about the health of available links.
The key buyer question is therefore not “Does the firewall support SD-WAN?” but “Which applications should receive which treatment?” During planning, the network team should identify critical applications, permitted egress paths, acceptable degradation and failover behaviour. It should also decide whether a session should remain on its current link for stability or move when a better path appears. Health-check targets need to represent the network the application actually uses; a probe to a nearby internet address may not reveal a problem farther along the path to a SaaS service. FourTeck can help translate business applications and circuit details into a configuration scope that the implementation team can validate.
Performance objectives should remain realistic. SD-WAN can choose among available links; it cannot create bandwidth that the ISP does not provide or remove congestion outside the organisation’s control. If all underlay links are impaired, steering has limited options. That is why resilient procurement includes carrier diversity, circuit capacity, handoff design, addressing, last-mile risk and backup connectivity as well as the FortiGate itself.
Security at the WAN edge changes the branch design
Traditional branch networks often sent internet traffic back to a central data centre because the organisation’s security stack lived there. As SaaS usage grows, that architecture can increase latency and WAN utilisation. A FortiGate at the branch can combine local internet connectivity, SD-WAN decisions and firewall policy at the same edge. This makes local breakout a practical option, but local breakout should never be interpreted as uncontrolled direct internet access. The branch still needs appropriately licensed and configured security inspection, segmentation, DNS policy, authentication, logging and administrative protection according to the organisation’s risk model.
Fortinet’s platform approach is relevant because routing, SD-WAN and NGFW policy live in the FortiOS environment. The commercial and performance impact still depends on which inspection functions are enabled. Deep inspection, application control, intrusion prevention, web filtering and other subscribed services can affect throughput and hardware sizing. A procurement sheet that compares only raw firewall throughput may therefore undersize a branch expected to inspect encrypted traffic at high speed.
Security architecture should also cover east-west and branch-to-branch communication. An overlay that makes connectivity easier can create broad reachability if segmentation is not planned. VPN topology, route advertisement, firewall zones and policies should restrict access according to business need. For organisations with guest Wi-Fi, CCTV, point-of-sale, operational technology, corporate users and servers at the same location, network segmentation can be as important as WAN path selection. FourTeck’s firewall services and configuration support can be included in the discussion when the project requires more than product supply.
Central management matters more as the site count grows
A two-site deployment can be managed very differently from a fifty-site or multi-region estate. FortiManager is designed to centralise FortiGate management and can provide SD-WAN monitoring, templates, policy packages and operational workflows. Fortinet documentation also describes zero-touch provisioning and overlay-management options that can simplify deployment at scale. This does not mean every customer must buy the same central-management architecture. A small deployment may operate directly on individual FortiGates, while a large enterprise may need administrative domains, change approval, automation, API integration and separate NOC and security workflows.
Before selecting the management model, ask who will operate the WAN after deployment. If an internal IT team owns daily changes, it may value standardised templates, role-based administration and a repeatable troubleshooting process. If a service provider or integrator performs changes, responsibilities for access, backups, logging, upgrades and incident response should be documented. Where FortiAnalyzer or analytics services are considered, logging volume, retention, reporting expectations and entitlement should be confirmed. Management design also affects migration: introducing central control after dozens of branches are already deployed can require additional standardisation work.
Automation should be used to make known processes repeatable, not to hide an unclear design. Branch naming, address objects, overlays, SLA targets and policy packages must still be engineered deliberately. FourTeck can help buyers decide whether their requirement is a simple FortiGate SD-WAN deployment, a FortiManager-managed estate, a broader SD-Branch project or a future SASE transition. For related Fortinet firewall options, buyers can also review Fortinet firewall guidance from FourTeck.
Ideal business environments and use cases
Retail and hospitality branches
Stores, restaurants, hotels and service locations may combine payment, guest, corporate, voice and cloud traffic. SD-WAN can provide differentiated path policy, while segmentation and security policy separate business systems from guest or device networks. Circuit diversity and application dependency should be documented site by site.
Logistics and warehouse networks
Warehouses often rely on scanners, ERP access, CCTV, wireless infrastructure and cloud services. A backup internet path may be valuable where operations cannot wait for a single circuit repair. The FortiGate must be sized for WAN, VPN, inspection and the local segmentation requirement.
Clinics and professional offices
Distributed offices may need controlled access to hosted applications, headquarters systems and internet services. Secure SD-WAN can help separate traffic priorities, but confidentiality, identity, logging and access policy remain part of the security design.
Education and training sites
Schools and training centres can have high-volume internet usage alongside administrative systems and cloud platforms. Multiple links and application-aware policy may help use available bandwidth more intentionally, subject to appropriate filtering subscriptions and acceptable-use requirements.
Regional enterprises
Organisations with many branches and regional hubs may use VPN overlays, dynamic routing, ADVPN, central management and standardised templates. Scale makes routing design, address planning and operational governance especially important.
Cloud-first organisations
Where users rely primarily on SaaS, local internet paths can be more appropriate than central backhaul. Secure SD-WAN can form part of a wider SASE strategy, but user licensing, cloud security policy and remote-user requirements should be reviewed independently.
Integration and operational considerations
Secure SD-WAN sits in the middle of routing, security, carrier services and application delivery, so the integration plan should be detailed. Existing branch networks may use static routes, OSPF, BGP, IPsec tunnels, VLANs, DHCP, DNS forwarding, NAT and inbound publishing. Some applications may depend on a fixed source IP, while others use geolocation or session persistence. Voice platforms may be sensitive to path changes. Cloud firewalls, data-centre routers and third-party VPN peers may have route limits or encryption requirements. These details influence how quickly a branch can migrate and whether a staged coexistence period is needed.
High availability deserves special treatment. An HA pair at a hub can reduce appliance failure risk, but the design also needs redundant switches, diverse WAN handoffs, correct routing, power resilience and a tested failover process. Branches may use one FortiGate with two circuits or two appliances depending on business criticality. There is no universal topology. A design should balance outage impact, budget, operational complexity and recovery requirements.
Software versioning is also part of operations. FortiOS features and supported capabilities evolve, and a large estate should have an upgrade policy rather than running arbitrary releases at different sites. Before an upgrade, teams should review release notes, known issues, compatibility with FortiManager, VPN peers and central logging, and the rollback plan. Configuration backups and change documentation are essential. Buyers who need assistance with these activities can include configuration, migration or support scope when requesting a quotation through the FourTeck contact team.
Questions to resolve before a quotation is prepared
Separate small branches, large branches, hubs, data centres and cloud edges. Their interface, performance and resilience requirements may be different.
Record provider, speed, handoff, addressing, public IPs, MPLS or private routing and any backup links. Planned circuits should be distinguished from live ones.
Identify voice, ERP, Microsoft 365, private applications, cloud services and traffic that has strict latency or continuity requirements.
Inspection requirements affect FortiGate sizing and subscriptions. Confirm IPS, malware protection, web filtering, application control, DNS security, SSL inspection and support needs as applicable.
Decide whether local administration is enough or whether FortiManager, analytics, automation, operational dashboards or delegated administration are required.
Collect current routes, NAT, VPNs, VLANs, server publishing, remote access, monitoring and application dependencies so the new WAN does not accidentally break required services.
Procurement checklist for FortiGate Secure SD-WAN
How FourTeck can support the project
FourTeck can help businesses turn a broad Secure SD-WAN objective into a purchase-ready requirement. That may begin with a review of existing FortiGate devices, branch locations, WAN bandwidth, ISP services, MPLS dependencies, applications, VPN topology and security subscriptions. The next step is to decide whether existing appliances can support the intended design or whether new FortiGate models are required. Where several models are involved, the bill of materials can distinguish branch devices, hub devices, HA pairs, transceivers, cellular options, FortiCare, FortiGuard services, management licenses and other project components.
Configuration support can be scoped separately from product supply. Some customers need only quotation and delivery coordination; others need SD-WAN member creation, health checks, routing, IPsec overlays, application steering, firewall policy, migration from existing routers, FortiManager onboarding, testing and documentation. The quotation should state what is included rather than assuming installation or configuration is automatic. FourTeck can also help review renewal timing, support entitlement and future capacity so a deployment does not become difficult to maintain shortly after purchase.
For broader planning, visit Firewall Dubai by FourTeck or discuss a requirement directly with the sales team.
UAE availability and support guidance
Contact FourTeck to confirm current UAE availability for the required FortiGate models, FortiCare and FortiGuard terms, SD-WAN service bundles, management components and accessories. Availability can depend on model, hardware generation, license term, quantity, region and vendor lead time. A project quote should therefore identify the exact appliance and commercial bundle rather than use “Secure SD-WAN” as a single line item with unclear inclusions. Delivery and project coordination can be discussed after the requirement is confirmed, and installation or configuration scope should be included in the quotation when required.
For existing FortiGate customers, it may be possible to introduce SD-WAN without replacing every appliance, but suitability depends on software support, hardware capacity, ports, current subscriptions and the performance expected after security inspection. FourTeck can review the current estate and advise what needs confirmation before a migration plan is prepared.
Dubai, Abu Dhabi, Sharjah and Ajman project coordination
Businesses operating across Dubai, Abu Dhabi, Sharjah and Ajman can approach FourTeck with one regional requirement even when individual sites have different WAN conditions. The planning discussion can separate headquarters, branches, warehouses, retail outlets, clinics or project offices, then map each location to its circuit, bandwidth, FortiGate role and support expectation. Current availability, site coordination, installation scope, warranty handling and delivery arrangements should be confirmed for the specific project. This combined approach is useful for organisations that want common policy and management but do not want to assume every branch needs identical hardware. FourTeck can also coordinate with customer IT teams, ISPs and existing network providers when responsibilities are clearly defined in the project scope.
GCC Availability
FourTeck can assist organisations planning FortiGate Secure SD-WAN projects across GCC markets with requirement review, model selection, licensing discussion, quotation coordination and regional deployment planning. A company with sites in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman may want a common technical standard while still purchasing circuits, hardware and services according to local conditions. The first step is to share the destination country for each site, required FortiGate role, quantity, preferred license term, expected implementation schedule and whether configuration or installation assistance is required. Product availability, licensing, service visits, lead times and project scope can vary by country, model and quantity. WAN carriers, power standards, addressing, cloud access and local operational ownership may also differ. FourTeck can help structure these variables into a bill of materials and implementation discussion without assuming identical logistics in every market. For Kuwait-related enquiries, buyers may also use the FourTeck Kuwait platform.
Africa Availability
Organisations with branches or projects in Africa can contact FourTeck for guidance on FortiGate models, licenses, accessories, subscriptions, management requirements, configuration scope, renewals and procurement planning. An SD-WAN design for Kenya, Uganda or another African market should take the actual destination and connectivity environment into account. Availability and fulfilment can depend on product generation, quantity, licensing region, local power or regulatory requirements, shipping arrangements, vendor lead time, installation scope and site readiness. WAN quality and carrier diversity also vary considerably between locations, which can affect the best underlay strategy even when the FortiGate configuration standard is shared. Buyers should provide the destination country, branch count, circuit types, target bandwidth, required quantity, preferred deployment window and any onsite or remote-support expectations. FourTeck can then help identify what needs to be quoted and what must be verified locally. Regional enquiries can also be routed through FourTeck Africa.
Related products and services to consider
FortiGate NGFW appliances
Select branch, campus or data-centre FortiGate models according to inspected performance, WAN and LAN interfaces, VPN, sessions and growth. The exact model is a core SD-WAN sizing decision.
FortiManager
Consider central policy, configuration, SD-WAN monitoring and orchestration when many FortiGates need consistent administration. Deployment and licensing should match device count and operating model.
FortiAnalyzer and analytics
Logging and analytics can support troubleshooting and operational visibility. Retention, reporting, deployment model and entitlements should be confirmed separately.
FortiExtender and cellular WAN
Cellular connectivity may be useful as primary or backup transport at selected sites. Carrier, signal, data plan, antenna and compatibility requirements must be checked for the location.
FortiSASE
Businesses extending secure access to remote users and cloud applications may evaluate FortiSASE alongside SD-WAN. User seats, service tier and integration scope are subscription dependent.
Migration and configuration services
A move from static routing, MPLS-centric WANs or another SD-WAN platform may require discovery, overlay design, policy conversion, staged cutover, testing and documentation.
What buyers are really trying to decide about Secure SD-WAN
Many buyers start with a simple question: is Secure SD-WAN a replacement for MPLS, a firewall feature, or an entirely new managed network? The practical answer can be all three in different projects, which is why the architecture must be defined before pricing is compared. FortiGate SD-WAN can run across internet, private and other supported transports, so an organisation does not have to remove MPLS on day one. A common migration is hybrid: retain private connectivity for selected traffic, introduce broadband for cloud and internet use, then use SD-WAN policy to decide how each path is used. Over time, the business can evaluate whether expensive private circuits are still justified by application and risk requirements.
Is SD-WAN free on FortiGate?
The base FortiGate SD-WAN functionality does not require a separate SD-WAN feature license. That does not make the whole project free. Hardware, FortiCare, FortiGuard subscriptions, central management, analytics, cloud services, SASE user licensing and implementation can all affect the commercial scope. Ask the supplier to separate these line items so the quotation is easy to compare.
Do I need FortiManager?
Not for the existence of SD-WAN itself. FortiManager becomes increasingly valuable when a business wants central configuration, templates, policy packages, monitoring and scalable operations across many devices. Small environments may decide that direct FortiGate administration is sufficient. Larger environments should evaluate the cost of operational inconsistency as well as the cost of the management platform.
Another frequent comparison is SD-WAN versus dual-WAN failover. Basic dual-WAN can switch traffic when a link fails, while an SD-WAN design can make more granular decisions based on traffic class, policy and measured link quality. A company whose only requirement is “use link B when link A is down” may not need a complicated overlay. A company running voice, video, cloud ERP, backups and private applications across several providers can gain more value from application-specific policies. The decision should be proportional to the real network problem.
Buyers also ask whether SD-WAN automatically improves Microsoft 365, Teams, Zoom or other SaaS performance. It can improve path choice when a better link is available and can reduce backhaul where local breakout is appropriate. It cannot guarantee application performance across the public internet. SaaS experience still depends on ISP routing, peering, endpoint condition, Wi-Fi, DNS, cloud service health and available bandwidth. For voice and video, define measurable SLA thresholds and test them during a pilot instead of assuming generic settings will suit every circuit.
Pricing questions are best answered by breaking the solution into four layers. First is the FortiGate hardware or virtual appliance sized for each site. Second is the support and security subscription, which determines update and inspection entitlements. Third is the management and optional service layer, which may include FortiManager, analytics, SD-WAN service bundles, FortiGate Cloud functions or SASE capabilities. Fourth is professional work: design, configuration, migration, testing and handover. Two quotations that both say “Fortinet SD-WAN” can be materially different if one includes only appliances and another includes multi-year security, central management and deployment services.
The most useful pre-sales document is therefore a site matrix. For every location, list user count, internet speed, private circuit speed, required ports, critical applications, current firewall, VPN peers, public IP requirements, high-availability need and expected security inspection. Add the preferred support term and whether the site can be configured remotely or requires installation coordination. This information enables more accurate FortiGate sizing and reduces the chance of discovering missing transceivers, licenses or capacity during rollout.
Organisations replacing another SD-WAN platform should also plan for policy translation rather than assuming feature names map one-to-one. Existing business intent may be preserved, but application classification, SLA measurements, tunnel design, routing and monitoring can work differently. Capture the reason behind each current rule before rebuilding it. If a policy exists only because of an old carrier limitation, the new architecture may not need it. If it protects a critical ERP route, it deserves explicit validation after cutover.
Finally, consider operations after deployment. Who changes an SLA threshold when a carrier changes? Who monitors a degraded link that has not fully failed? Who upgrades FortiOS across branches? Who keeps configuration backups and renews subscriptions before expiry? A Secure SD-WAN project is more successful when these ownership questions are answered before the first site goes live. FourTeck can help buyers prepare the model, license and implementation questions needed for a quotation rather than treating SD-WAN as a generic appliance purchase.
Questions that shape the right design before you buy
Can I keep my existing MPLS circuit and still use SD-WAN?
Yes, an SD-WAN design can include different underlays rather than forcing an immediate MPLS removal. The important question is how routes, SLA rules and security policies should use each transport. Some organisations keep MPLS for private applications while moving SaaS and internet traffic to broadband, then reassess after monitoring real performance.
Should every branch use the same FortiGate model?
Not necessarily. Standardisation can simplify operations, but a warehouse with high camera traffic, a small office and a regional hub may have different throughput, interface and redundancy needs. Use a limited set of validated models where practical, but size each site role based on inspected traffic and growth.
What does the implementation team need from the ISP?
For each circuit, collect speed, handoff type, VLAN details if used, static or dynamic addressing, public IP allocation, upstream gateway, routing information and escalation contacts. If resilience is required, verify whether the two services are genuinely diverse or share the same physical last mile.
How do I know which security bundle is needed?
Start with the controls the organisation expects to enforce at the branch: intrusion prevention, malware protection, application control, web filtering, DNS security, SSL inspection, support and updates. Then match those requirements to the current Fortinet offer for the selected model and term. Do not choose a bundle solely by name.
Can SD-WAN solve an unreliable internet connection?
It can route around a degraded path when another acceptable path exists, but it cannot repair an ISP. If both circuits share the same failure point or both are congested, the FortiGate has limited alternatives. Circuit diversity and carrier planning remain essential parts of resilience.
What should be tested before moving all branches?
Validate link failure and recovery, application path selection, VPN reachability, security inspection, voice and video behaviour, cloud access, DNS, public services, monitoring, management and support procedures. A representative pilot branch can reveal assumptions that are difficult to see in a spreadsheet.
These questions help separate product selection from architecture. Once the answers are known, FourTeck can assist with FortiGate sizing, current bundle confirmation, quotation preparation and configuration scope. That reduces the risk of buying hardware first and discovering later that the required interfaces, support term, management architecture or implementation work were not included.
Why businesses contact FourTeck for Secure SD-WAN planning
The value of a pre-sales discussion is practical clarification. Buyers may know that they want Fortinet SD-WAN but still need to decide which FortiGate models fit each site, whether existing hardware can be reused, which security services are required, how long the support term should be, whether FortiManager belongs in the design, and which accessories or transceivers are needed. FourTeck can help organise those questions into a bill of materials and quotation request.
The same applies to deployment scope. Product supply, remote configuration, onsite installation, MPLS migration, VPN redesign, FortiManager onboarding, testing and documentation are different activities. A clear quotation defines which are included. This is especially useful for multi-site projects where branches may be rolled out in phases and where ISP readiness is outside the firewall supplier’s control. Buyers can learn more about FourTeck through the FourTeck Firewall Dubai information page.
Frequently asked questions
Does FortiGate require a separate license just to enable SD-WAN?
Fortinet states that the base SD-WAN functionality can be enabled on FortiGate without a separate SD-WAN feature license. Security subscriptions, support, central management, cloud services and SD-WAN service bundles can still have separate commercial requirements.
What FortiGate model is suitable for my branch?
The model should be selected from inspected throughput, internet and private-link speed, user count, VPN traffic, required interfaces, security services, sessions, high-availability needs and growth. FourTeck can review these inputs before recommending a model range.
Can FortiGate Secure SD-WAN use MPLS and internet together?
Yes, different WAN transports can participate in an SD-WAN design. The exact routing, SLA and overlay configuration depends on the carrier services, addressing, security requirements and applications that must use each path.
Is FortiManager mandatory?
FortiManager is not mandatory simply to use SD-WAN on a FortiGate. It is commonly considered for central management, templates, monitoring and orchestration, particularly as the number of devices and administrators grows.
Does Secure SD-WAN guarantee better application performance?
No. It can choose among available paths based on policy and measured health, which may improve application experience when a better path exists. End-to-end performance still depends on WAN quality, ISP routing, bandwidth, cloud services, endpoints and correct configuration.
Can I use direct internet access from branches?
Yes, local internet breakout is a common SD-WAN design option. The branch must still have suitable firewall policy, security subscriptions, DNS, logging and identity controls. Whether traffic should break out locally is application and security-policy dependent.
What information should I send for a UAE quote?
Provide site count, user count, WAN circuit speeds and types, current FortiGate or router models, required security services, critical applications, VPN requirements, preferred support term, management needs, quantity and whether configuration or installation support is required.
Can FourTeck help migrate an existing branch network?
Migration assistance can be discussed as part of the project scope. Work may include existing configuration review, routing and VPN planning, SD-WAN policy creation, firewall-policy migration, testing and handover. The exact scope depends on the current platform and network documentation.
How do I confirm current availability and licensing?
Contact FourTeck with the exact site requirement and preferred term. Availability, bundle structure, accessories, support and vendor lead time can change, so the final quotation should confirm the exact model and license combination before ordering.
Build the quotation around your actual WAN
Share your branch count, WAN circuits, current FortiGate estate, key applications, security requirements, management preference and migration priorities. FourTeck can help identify the FortiGate roles, commercial bundles and implementation items that need to be confirmed for a Dubai or UAE Secure SD-WAN project.