Enterprise Networking 17 min read

How to Choose an SD-WAN Solution
For Multi-Site Operations

Connecting branch offices, retail locations, and logistics warehouses across Canada shouldn't require exorbitant MPLS contracts or suffer from frequent dropped VoIP calls. Here is how to evaluate and deploy enterprise SD-WAN with sub-second failover.

Published September 2026
QueryTel Enterprise Network Engineering

Executive Takeaway

Traditional hub-and-spoke MPLS networks "hairpin" all branch internet traffic through a central corporate data center firewall before letting it reach cloud apps like Microsoft 365, Salesforce, and ERPs. Software-Defined Wide Area Networking (SD-WAN) bonds low-cost commercial fiber, cable, and 5G connections to deliver sub-second line failover, direct-to-cloud security, and 60% lower carrier bandwidth bills.

01

Why Legacy WAN is Breaking Under Multi-Site Demands

Ten years ago, all business applications lived inside the headquarters server room. It made sense to connect branch offices with dedicated private MPLS (Multiprotocol Label Switching) circuits.

Today, over 80% of business applications live in the public cloud (AWS, Azure, Microsoft 365, NetSuite). Backhauling cloud traffic from a remote distribution facility in Calgary through an MPLS pipe to an Ontario head office just to inspect packets before sending them out to the internet introduces destructive latency, video stutter, and massive bandwidth bottlenecks.

The "Hairpin" Bottleneck

When a warehouse barcode scanner or branch user opens a cloud ERP, packets travel: Branch → Slow MPLS Circuit → HQ Firewall → Public Internet → Cloud → HQ Firewall → MPLS Circuit → Branch. This doubles latency and wastes expensive leased line capacity.

02

How SD-WAN Solves the Multi-Site Problem

SD-WAN separates the control plane (network intelligence, routing policies, QoS) from the underlying physical transport (the physical circuits). Instead of being locked into a single telecom provider's proprietary circuit, SD-WAN treats any available internet connection as an aggregated transport pool:

Circuit Bonding & Active-Active

Combine a primary dedicated fiber line, a low-cost commercial cable backup, and a 5G cellular SIM into a single virtual tunnel. Both lines pass traffic simultaneously rather than leaving backup lines idle.

Sub-Second Packet Steering

SD-WAN measures packet loss, jitter, and latency on every link every 100 milliseconds. If the primary fiber experiences a brownout, active VoIP phone calls and video conferences seamlessly steer to the backup link without dropping the call.

Direct Cloud On-Ramping

Trusted SaaS applications (Teams, Zoom, M365) break out directly to the internet at the branch edge, while sensitive database queries route encrypted over the private VPN overlay to headquarters.

03

MPLS vs. SD-WAN: The Cost & Performance Reality

Why are North American enterprises actively replacing MPLS contracts? Look at the cost-per-megabit math:

Feature / Metric Legacy MPLS Leased Lines Managed SD-WAN (QueryTel)
Bandwidth Cost $250 – $600/month for a meager 20–50 Mbps pipe. $80 – $150/month for 500 Mbps – 1 Gbps commercial fiber.
Carrier Lock-in Single carrier mandated across all branches. Multi-year lock-in. Carrier-agnostic. Mix Bell, Rogers, Shaw, Starlink, or Telus.
Deployment Time 60 to 120 days lead time for telco engineering crews. Days. Zero-touch provisioning appliances ship pre-configured.
Failover Mechanics Passive backup. Takes 30–90 seconds to renegotiate routes (all calls drop). Sub-second dynamic failover with zero packet loss or call drops.
Direct Cloud Access Requires backhauling to central HQ proxy. Native local breakout with automated Layer 7 application identification.
04

5 Non-Negotiable Criteria When Choosing SD-WAN

01

True Application-Aware Layer 7 Routing

Basic routers only look at IP addresses and port numbers. Modern SD-WAN identifies over 5,000 specific applications (e.g. prioritizing an active Microsoft Teams video stream over a warehouse user downloading a YouTube video).

02

Integrated Next-Gen Firewall (NGFW) Security

Opening local internet breakouts at every branch without security is catastrophic. Ensure your SD-WAN solution (like Fortinet FortiGate) includes Deep Packet Inspection, IPS, Antivirus, and Web Filtering built natively into the same ASIC hardware.

03

Zero-Touch Provisioning (ZTP)

When opening a new warehouse in Halifax or a retail clinic in Vancouver, you shouldn't have to fly a senior network engineer onsite. A non-technical branch worker plugs the box into power and internet, and the device pulls its cryptographic configuration from the cloud console automatically.

04

Integrated 5G/LTE Failover with Out-of-Band Management

If construction crews sever your street's primary fiber conduit, embedded 5G modems keep mission-critical ERP transactions flowing while giving remote engineers console access to troubleshoot the physical link.

05

Single-Pane-of-Glass Central Orchestration

Managing 15 separate branch firewalls with independent configuration files leads to human error and compliance drift. Centralized cloud orchestration pushes policy updates to all sites simultaneously in one click.

05

The Convergence: Secure SD-WAN & SASE

The industry has moved beyond standalone SD-WAN routers. Connecting locations securely requires SASE (Secure Access Service Edge): the union of software-defined networking with comprehensive cloud-delivered security.

On-Premise Secure SD-WAN

Utilizing high-performance hardware appliances such as Fortinet FortiGate Firewalls. Dedicated security processors (SPUs) inspect encrypted SSL/TLS traffic at multi-gigabit speeds without degrading network throughput.

Ideal for branch offices & warehouses

Cloud SASE for Remote Workers

Extends the exact same security policies to work-from-home employees and travelling executives. Remote endpoints connect through lightweight cloud agents with Zero Trust Network Access (ZTNA) without needing clunky full-tunnel VPNs.

Ideal for hybrid & remote teams
06

Recommended Topology for Canadian Multi-Site Operations

For businesses with a corporate headquarters, multiple branch offices, and distributed distribution or manufacturing warehouses, QueryTel designs a resilient Hybrid Mesh SD-WAN topology:

Headquarters / Primary Data Center

Dual 1 Gbps symmetrical dedicated fiber circuits from independent carriers (e.g. Bell & Rogers) running through high-availability clustered FortiGate firewalls.

Regional Warehouses & Distribution Centers

Commercial broadband fiber paired with high-gain 5G cellular failover. Automated QoS prioritizes Zebra barcode scanners, warehouse management systems (WMS), and security camera feeds over guest Wi-Fi.

Retail / Small Branch Clinics

Compact desktop SD-WAN appliances with integrated Wi-Fi 6, ensuring PCI-DSS compliant point-of-sale transaction isolation from public guest networks.

07

Pre-Deployment Evaluation Checklist

01.

Inventory all current ISP contracts across every branch: expiration dates, monthly spend, and bandwidth caps.

02.

Classify corporate applications into tier-1 latency-sensitive (VoIP, ERP) vs tier-2 background (cloud backups, updates).

03.

Test secondary carrier availability at each branch location to avoid sharing the same physical fiber conduit.

04.

Execute a Proof-of-Concept (POC) pulling the physical cable during an active video call to test seamless failover.

08

Frequently Asked Questions

Can we migrate from MPLS to SD-WAN gradually?

Yes! QueryTel regularly deploys "hybrid WAN" architectures where SD-WAN appliances bond existing MPLS lines alongside new high-speed broadband fiber. As your long-term telco contracts expire, you simply decommission the MPLS circuits with zero downtime.

Does SD-WAN replace our existing internet service providers?

No, SD-WAN operates on top of your ISPs. It allows you to buy internet from whatever provider offers the fastest, most affordable speeds in each specific city (Bell, Rogers, Cogeco, Starlink) while managing them under one unified network.

How fast is the failover if a primary internet link goes down?

Sub-second (under 300 milliseconds). In fact, with packet duplication technologies enabled for voice traffic, phone calls and Teams conferences continue without the user ever detecting that an ISP link failed.

Complimentary Multi-Site Network Audit

Ready to Slash WAN Bandwidth Costs and Eliminate Branch Downtime?

Connect with QueryTel's certified network engineers. We will analyze your current branch circuits, simulate SD-WAN application acceleration, and deliver a comprehensive multi-site migration blueprint.

Was this SD-WAN evaluation guide helpful?

Help us tailor our network architecture content for business leaders and IT teams.