Skip to main content
vicctor
New Member
March 15, 2026
Question

Best Practices for Sizing an SD-WAN Hub

  • March 15, 2026
  • 1 reply
  • 321 views

Hi everyone,

 

I am relatively new to the Fortinet world and I’m currently working on my first SD-WAN deployment exercise. I’m at the stage where I need to select the right FortiGate model to act as the Hub, but I want to make sure I don't under-provision the hardware or over-spend unnecessarily.


Could you help me identify the critical variables I should consider for the correct sizing of the Hub? From my initial research, I’m looking into: Total Number of Spokes, Tunnel Count, Routing Table Size.

 

Beyond these, what else am I missing? For example, how do I calculate the impact of security profiles (IPS, Antivirus, Application Control) when they are applied at the Hub level in an SD-WAN architecture?

 

If there are any specific FortiGate Sizing Guides or "rules of thumb" you use when designing the Hub capacity, I would love to hear them.


Thanks in advance for your patience and help!

1 reply

AEK
SuperUser
SuperUser
March 16, 2026

Hi Victor

Check the FGT models for a quick comparison.

https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/Fortinet_Product_Matrix.pdf

In your case it is good to check the following columns:

  • Max GW to GW IPsec tunnels
  • IPsec VPN Throughput
  • Firewall / IPS / NGFW / Threat-Protection throughput

Other advice:

  • For hub we use HA, since a failure will simply kill the whole network
  • Avoid FGT models with 2GB RAM
  • Personally I'd not go under FG-120G as hub

Hope it helps.

AEK