FortiGate SD-WAN with fiber, Starlink, and cellular
Most offices still run on one internet circuit, and when it fails, so does everything that lives in the cloud — Microsoft 365, line-of-business apps, phones. FortiGate SD-WAN removes that single point of failure by treating several independent connections as one managed pool. A typical design pairs primary fiber with Starlink and a cellular circuit: three providers, three physical paths, very little shared risk.
The SD-WAN rules decide where traffic goes. Health checks continuously probe DNS, general internet reachability, and Microsoft 365 endpoints on every circuit; when a link goes down or drops below its performance thresholds, traffic steers to a healthy path automatically and moves back when the primary recovers. Failover is tested during the build, not discovered during the first outage.
This is how we rebuilt connectivity for the Volunteers of America National office: a FortiGate 121G managing fiber, Starlink, and cellular in SD-WAN zones, with health checks feeding route selection and failover verified before handoff.
VLAN segmentation, RADIUS, and knowing what is on your network
A flat network lets any compromised laptop talk to every server, printer, and camera. Segmentation splits the network into VLANs by device type and purpose — a dedicated management network, staff, wireless, infrastructure — and the FortiGate decides which segments may talk to each other. Access is granted on operational need, and anything unnecessary is removed during the policy review.
Segmentation works best alongside identity and inventory. Centralized RADIUS authentication replaces independently managed credentials on network gear, and a known-device MAC inventory makes unexpected devices stand out the moment they appear. Neither replaces the firewall policy; together they give administrators visibility and control that a single control cannot.
Network logs in Microsoft Sentinel, without the noise
Firewalls and switches generate enormous volumes of events, and forwarding all of them to a SIEM buys you a large bill and alert fatigue. We centralize network and infrastructure logs first — on Synology in the VOA National build — and forward them into Microsoft Sentinel, then review what actually arrives.
Repetitive and low-value events are filtered at the source, logging levels are adjusted, and the events that matter for detection and incident investigation are kept. The result is a Sentinel workspace administrators actually use, covering the network as well as Microsoft 365 and endpoints, which is where our cybersecurity program picks up.