Home / Services / Networks & SD-WAN
Networks & SD-WAN

Secure networking for every site, user and cloud connection

Branches, warehouses, manufacturing sites, clinics and project sites: wherever the business operates, performance, connectivity, cloud access, users, carriers and security controls have to work cleanly together. We engineer that layer end to end across firewalls, SD-WAN, remote access, ZTNA, SASE-aligned architecture, carrier links and segmentation, on platforms such as Fortinet and Cisco Meraki.

Operate across
SD-WANFirewallsSecure accessZTNASASECarrier linksCloud accessSegmentation
How we help

Network services across SD-WAN, secure access, firewalls and multi-site operations

It usually starts with one problem: a slow or unreliable site, a firewall nobody trusts, remote access, a carrier renewal or a SASE decision.

Not sure where the issue sits? A Network Review can help clarify the right pathway before a major decision, whether the next step is SD-WAN, firewall uplift, SASE/ZTNA, carrier change, cloud-path improvement, documentation or operating-model work.
Start with a Network Review
Secure networking services

How we support secure networking

Managed SD-WAN

Managed SD-WAN supports organisations running multiple sites, regional operations, warehouses, branches or distributed teams where connectivity, failover, application performance and centralised control matter.

The work isn't only about replacing links. It means designing and running a network that keeps every site connected, secure and visible. Where Fortinet is the right fit, FortiGate, FortiManager, FortiAnalyzer and SD-WAN can be managed as one operating environment.

Best for multi-site connectivity, failover and network visibilityExplore Managed SD-WAN →
SASE and Zero Trust Access

SASE and Zero Trust Access is for organisations whose workforce, contractors and applications no longer fit a perimeter-based access model. VPN may still be in place, but access may need to become more identity-aware, device-aware and application-specific.

The work can include Microsoft Entra ID hygiene, Conditional Access posture, device compliance, application dependency mapping, Entra Internet Access and Private Access design, ZTNA migration sequencing and Australian secure access requirements.

Best for VPN replacement, contractor access and secure application accessExplore SASE and Zero Trust Access →
FortiGate firewall and secure edge

FortiGate work is for organisations that want firm control of firewall policy, remote access, segmentation and lifecycle across their Fortinet estate.

This can involve firewall review, rule clean-up, policy redesign, FortiGate replacement, FortiManager and FortiAnalyzer alignment, VPN remediation, segmentation improvement, secure edge design and implementation. We run firewalls as a live system: policy reviews, firmware, logging and controlled change.

Best for firewall uplift, FortiGate implementation and secure edge improvementDiscuss firewall and secure edge →
Network design, deployment and operation

Network design and operation is for when the problem spans more than one piece: WAN, firewalls, remote access, carriers, cloud performance or SD-WAN and SASE readiness.

This is the broader pathway for organisations that need the network position clarified and then acted on. The output should not be a report that sits on a shelf. It ends with a clear next step: a design, a carrier decision, a firewall uplift or an SD-WAN rollout.

Best for unclear network direction, architecture decisions and implementation planningDiscuss your network environment →
The operating view

We design the network for how people work now

We connect head offices, branches, sites and people on the road to Microsoft 365, SaaS and Azure, with security built into every path.

Users work from more places. Applications sit in Microsoft 365, SaaS platforms, Azure, AWS and private infrastructure. Branches need stable cloud access. Firewalls need consistent policy. Remote access needs stronger control. Carrier decisions affect performance, resilience and ease of support.

CARRIER UNDERLAYNBN EE · Fibre · 4G / 5G · Satellite · MPLSHead officeBranch and warehouseClinic / project siteRemote and field usersSECURE EDGESD-WANFortiGate firewallSASE · ZTNAPolicy and inspectionMicrosoft 365 · TeamsSaaS platformsAzure · AWSPrivate infrastructureSITES and USERSCLOUD and APPLICATIONS
How we design the environment: sites and users, through a secure edge, to cloudCarrier underlay chosen per site

Connectivity

Sites, branches, warehouses, clinics, project locations and remote users need the right underlay, failover, routing and visibility.

Security

Firewall policy, segmentation, VPN, ZTNA, SASE, identity and access controls need to match how people and systems actually connect.

Cloud access

Microsoft 365, SaaS, Azure, AWS and private infrastructure need secure and efficient paths, not inherited backhaul or unclear routing.

Capability at a glance

Network capability at multi-site scale

110+
Site SD-WAN rollout
Large-scale SD-WAN deployment experience across distributed locations, with branch connectivity, failover, policy and operational visibility managed as one network.
150+
Sites supported
Experience supporting regional, multi-site and distributed environments where connectivity, security, carriers and cloud access need to work together.
Fortinet
and FortiGate
Firewall, SD-WAN, VPN, FortiManager, FortiAnalyzer and secure edge work across Fortinet environments.
Meraki
Cisco Meraki capability
Cloud-managed network support across switching, wireless, security appliances, visibility and multi-site administration.
Common starting points

Common reasons clients call us

A branch that performs poorly, a firewall no one wants to touch, VPN access that has become too broad, or a carrier decision that's about to be renewed without enough context.

01A site or branch performs poorlyManaged SD-WAN

Users experience slow applications, unstable connectivity or inconsistent performance, but the cause may sit across carrier links, routing, firewall policy, Wi-Fi, cloud access or application design.

Best fit: Managed SD-WAN →
02Firewall policy has become hard to trustFortiGate firewall and secure edge

Rules have accumulated over time, VPN access is unclear, logging is weak, firmware is behind or no one is confident that the policy still reflects the business.

Best fit: FortiGate firewall and secure edge →
03VPN access is too broadSASE and Zero Trust Access

Remote users, contractors or administrators may have wider network access than they need, creating exposure that should be reviewed against ZTNA or SASE-aligned access options.

Best fit: SASE and Zero Trust Access →
04Carrier contracts are being renewedManaged SD-WAN

NBN Enterprise Ethernet, business fibre, broadband, 4G/5G, satellite or MPLS decisions should be reviewed against site criticality, application behaviour, failover and cost.

Best fit: Managed SD-WAN →
05SD-WAN is being consideredManaged SD-WAN

The business may need better failover, centralised control, application performance, carrier flexibility or operational visibility across multiple sites.

Best fit: Managed SD-WAN →
06SASE or ZTNA is unclearSASE and Zero Trust Access

The business may know that VPN needs improvement, but not whether the right pathway is ZTNA, SASE, Entra-aligned access, firewall uplift or a staged secure access roadmap.

Best fit: SASE and Zero Trust Access →
07A FortiGate is approaching end of supportFortiGate Lifecycle Checker

An end-of-support list has arrived, or a renewal is due, and the first question is whether the device actually needs replacing. Fortinet tracks three separate hardware dates, and FortiOS has a lifecycle of its own.

Best fit: FortiGate Lifecycle Checker →
Carrier and underlay

Built on Australia's major networks, engineered for your business

Australia's carriers build and run the networks every business depends on. We design across all of them, including Telstra, nbn, Vocus, Superloop, TPG Telecom and Starlink, and choose the right option for each site.

Their job is the connection. Ours is everything that makes a multi-site network dependable:

  • Multi-carrier resilience: active-active links across different carriers, with automatic failover when one drops.
  • Application performance: critical applications routed over the best-performing path in real time.
  • Security built in: segmentation, encrypted overlays and policy on FortiGate, managed with the rest of your security.
  • Fast site starts: 4G, 5G or Starlink to bring a site online while fixed links are provisioned, or as a permanent backup.
  • End-to-end management: design, hardware, carrier coordination, monitoring and lifecycle, with one point of accountability.
  • Direct escalation to engineers: straight to the SD-WAN engineers who know your network.

The carrier connects each site. We make sure the business keeps running across all of them.

You get a site-by-site view: what each location needs, what to renew, what to replace and what to fix before you sign anything.

Secure networking isn't only a carrier, firewall or SD-WAN decision. It's how the whole business stays connected, protected and accounted for.

How we work

How we work

We start with the sites and the people: where users connect from, what they need to reach, how the traffic gets there and who picks up the phone when a link drops.

01
Map the operating environment
Review sites, users, applications, firewalls, VPN, cloud paths, carriers, documentation and current ownership.
02
Identify performance and access pressure
Separate carrier issues, routing issues, firewall issues, access issues, Microsoft 365 performance problems and operating gaps.
03
Validate firewall and carrier position
Confirm the current firewall policy, VPN exposure, segmentation, lifecycle position and carrier underlay, so the design starts from the real operating state.
04
Design the secure network pathway
Set the architecture, underlay, security policy, access model, failover position and support approach before implementation.
05
Deploy, document and operate
Document, monitor, manage change, coordinate carriers and keep the network easy to support after deployment.
Why Inlight IT

Network engineering across sites, firewalls, carriers and secure access

We engineer networks that span many sites, several carriers and a lot of firewalls. We've rolled out SD-WAN to more than 110 sites, we run Fortinet estates day to day, and we document everything so it stays under control.

01

SD-WAN deployment experience

Large-scale SD-WAN deployment and operating experience across distributed sites, branch networks, carrier links, failover and centralised visibility.

02

Fortinet and secure edge depth

FortiGate, FortiManager, FortiAnalyzer, VPN, firewall policy, segmentation and secure edge design.

03

Carrier-agnostic advice

Underlay chosen site by site across every major carrier, based on performance, resilience and cost.

04

SASE and ZTNA planning

Secure access design across identity, device posture, application access, VPN replacement and SASE-aligned architecture.

05

Cloud access context

Network decisions considered against Microsoft 365, SaaS, Azure, AWS, private infrastructure and branch application performance.

06

Operational documentation

Design, deployment, handover, diagrams, escalation paths and support documentation so the network can be operated after change.

Recent work

Networks we’ve built and run

Common questions

SD-WAN and network questions

What does secure networking mean in practice?

Secure networking means the network is designed and operated around access, performance, resilience and security. It includes sites, users, firewalls, switching, wireless, cloud access, remote access, carrier links and segmentation.

The goal is to make sure people can access the systems they need without creating unnecessary exposure or unmanaged technical risk.

When should a business review its network?

A network review is useful when the business has recurring outages, poor application performance, unclear firewall rules, unreliable site connectivity, weak remote access controls or poor visibility across carriers and devices.

It's also useful before a major change, such as SD-WAN, SASE, cloud migration, firewall replacement, office relocation or contract renewal.

Is SD-WAN the same as SASE?

No. SD-WAN focuses on connectivity, traffic routing, path selection, link resilience and application performance across sites and internet links.

SASE is broader. It combines networking and security controls for users, sites and cloud access, often with stronger identity-aware access and cloud-delivered security.

When should we consider SD-WAN?

SD-WAN is worth considering when the business has multiple sites, unreliable internet links, expensive carrier services, cloud application performance issues or a need for better failover.

We base the decision on how critical each site is, how your applications behave, your security requirements and what each carrier can offer.

Should we replace MPLS with SD-WAN?

Not automatically. MPLS may still be suitable for some environments, especially where specific latency, private connectivity or performance requirements exist.

Many businesses now use SD-WAN to combine multiple links, improve resilience and support cloud access more flexibly. The right answer depends on the sites, workloads, carriers and risk profile.

Do we need ZTNA if we already have VPN?

Possibly. VPN can still be suitable for some use cases, but it often provides broader network access than the user actually needs.

ZTNA can provide more controlled access to specific applications or resources based on identity, device posture and policy. It's especially useful where remote access needs to become more secure and less network-wide.

When does a firewall review make sense?

A firewall review makes sense when rules have accumulated over time, remote access is unclear, logging is weak, firmware is outdated, segmentation is poor or no one is confident that the policy set still reflects the business.

We review exposure, admin access, VPN and ZTNA settings, rule hygiene and logging, and whether the firewall still fits how you work.

What does a Network Review cover?

A Network Review can cover site connectivity, carrier links, firewalls, routing, switching, wireless, remote access, segmentation, SD-WAN readiness, cloud access, monitoring, resilience and documentation.

The output should show what is working, what is fragile, what is risky and what should be improved before the next major outage, renewal or project.

Work with Inlight IT

Planning a network change?

Tell us what's happening across sites, firewalls, carriers or remote access, and we'll find the starting point.

Prefer email? contact@inlightit.com.au