Bizix GroupChecking status…
Home/Insights/Article

SD-WAN for multi-site Australian businesses: resilience over NBN, fibre, Starlink and 4G

What SD-WAN is, how it keeps sites connected across NBN, fibre, Starlink and 4G, and the situations where a simple VPN is the better answer.

A business with more than one site has always had the same problem: how to connect the sites to each other and to the systems they share, reliably, without paying for private circuits everywhere. SD-WAN is the current answer, and unlike some networking acronyms it describes something concrete and useful. It also gets sold to businesses that do not need it.

What SD-WAN actually is

Software-defined WAN separates the decision about where traffic goes from the physical links it travels on. Each site has an edge device with two or more connections behind it: an NBN service, a fibre service, a Starlink dish, a 4G or 5G modem. The edge builds encrypted tunnels across all of them to the other sites and to a hub, and a central controller pushes down policy describing which applications should use which path and what to do when a path degrades.

The “software-defined” part refers to that central policy. Instead of configuring routing on every site’s router by hand, the administrator describes intent once, for example that voice should take the lowest-latency path and bulk backups should take the cheapest, and every edge applies it. Adding a site means adding a device and letting it pull its configuration.

Resilience across NBN, fibre, Starlink and 4G

The reason SD-WAN exists is that no single connection in Australia is reliable enough on its own for a business that depends on it. NBN services fail, and their performance varies with contention and technology type. Fibre is excellent where it can be had. Starlink has changed what is possible for regional and remote sites, but it has its own characteristics: latency that varies, brief interruptions as satellites hand over, and throughput that drops in heavy weather. 4G and 5G are useful as backup and occasionally as primary in areas where nothing else reaches.

SD-WAN turns these into a portfolio rather than a choice. The edge continuously measures loss, latency and jitter on every path, and moves traffic between them in real time. A voice call in progress can shift from a degrading NBN link to Starlink without dropping. A backup can be held off Starlink during the day and released overnight. The failure of any one connection becomes a monitoring event rather than an outage.

For remote sites the combination that works well in our experience is Starlink as primary with 4G as backup, with the edge device handling the handover so that on-site systems never notice.

What it does to the security model

Because every site is reached through an encrypted tunnel from a managed edge, SD-WAN also tidies up security. Internet-bound traffic can be routed through a central inspection point, so a small branch gets the same intrusion prevention as head office without its own appliance. Segmentation between sites, or between staff and guest networks within a site, is policy rather than cabling. And because the controller knows every edge, a lost or stolen device can be revoked centrally.

None of this replaces endpoint security or identity controls, but it removes the common situation where the branch office has a consumer router and nobody has any visibility at all.

When SD-WAN is overkill

Not every multi-site business needs it. SD-WAN is typically unnecessary when:

  • there are two sites and the traffic between them is light and tolerant of a short outage
  • everything the business uses is a cloud application and the sites only need decent internet
  • a single good fibre service is available at each site and downtime is not costly
  • the organisation has no one to own the platform after it is installed

In those cases a well-configured pair of routers with a simple site-to-site VPN, and perhaps a 4G failover, does the job with far less to manage. The value of SD-WAN grows with the number of sites, the diversity of connection types, and the sensitivity of the business to outages. Below a certain threshold it is complexity for its own sake.

Designing for Australian conditions

A few things distinguish a design that works here from one copied from an overseas template. Connection diversity should be real: two NBN services from two retailers sharing the same physical fibre are one connection wearing two hats. Starlink needs a clear view of the sky and a mounting arrangement that will survive wind. 4G backup should be tested under load, not just observed to have signal. Sites with unreliable power need the edge device on a battery, or the resilience is theoretical.

The hub, where site tunnels terminate, should be somewhere with good connectivity to the systems the sites need: a private cloud in an Australian data centre, or head office if that is genuinely where the systems live. Placing the hub in the wrong place adds latency to every packet, and a design that looks tidy on a diagram can feel slow at every site.

Where Bizix fits

Bizix designs and builds multi-site networks for Australian businesses, including SD-WAN across NBN, fibre, Starlink and mobile services, with structured cabling and the Linepost hosted PBX where voice is part of the same project. Our agritech work on remote-site SD-WAN over Starlink has shaped how we design for sites where the connection cannot be taken for granted.