01
Client Profile & Background
A leading retail and distribution enterprise with over 50 branch offices across Indonesia, including major cities like Jakarta, Bandung, Surabaya, and Medan. The company operates multiple warehouses and distribution centers that require real-time inventory management and seamless connectivity to the central ERP system. Their IT infrastructure includes a mix of on-premises servers at headquarters and cloud-based applications for sales and logistics. The enterprise has a growing need for unified communication, including VoIP and video conferencing, to support collaboration among geographically dispersed teams. With a workforce of over 2,000 employees, the company relies heavily on network uptime for daily operations, especially during peak seasons like Ramadan and Christmas.
The existing network architecture was built on a hub-and-spoke MPLS model with a single internet breakout at the head office. Branch offices connected via MPLS links with varying bandwidths, ranging from 10 Mbps to 50 Mbps. However, as the business expanded, the centralized model led to high latency for cloud applications and single points of failure. The IT team, consisting of 10 engineers, struggled to manage network policies across different sites manually. There was no centralized visibility into network performance or security threats, making it difficult to troubleshoot issues proactively. The enterprise needed a scalable, resilient, and cost-effective multi-site network solution to support its growth and digital transformation initiatives.
02
Technical Challenge
The primary technical challenge was the high latency and packet loss experienced on the MPLS network, especially for cloud-based applications like Office 365 and Salesforce. Latency spikes reached up to 300ms during peak hours, causing slow application response times and frequent timeouts. Additionally, the hub-and-spoke topology meant that all internet traffic from branch offices had to traverse the head office, creating a bottleneck and increasing the risk of WAN link saturation. The enterprise also faced security vulnerabilities, as branch offices had no direct internet access and relied on a single firewall at headquarters, exposing the network to potential breaches if the head office link failed.
Another critical issue was the lack of redundancy. The MPLS links had no automatic failover, and in the event of a link failure, branch offices would be completely disconnected for hours. The company experienced at least three major outages in the past year, each lasting over 4 hours, resulting in significant revenue loss and operational disruption. Furthermore, the IT team had no centralized monitoring or management tools, making it impossible to enforce consistent security policies or perform rapid root-cause analysis. The enterprise needed a solution that could reduce latency to under 50ms for critical applications, provide automatic failover within seconds, and offer centralized orchestration for network and security policies.
03
Implemented Solution
Intilogy designed and deployed a multi-site SD-WAN solution using Cisco SD-WAN (Viptela) and Fortinet FortiGate firewalls for security. The architecture replaced the hub-and-spoke MPLS model with a full mesh topology, enabling direct internet access at each branch office while maintaining secure connectivity to the head office and cloud. We implemented Fortinet SD-WAN capabilities in the FortiGate devices to intelligently route traffic based on application type, link quality, and cost. For example, real-time traffic like VoIP was prioritized over low-latency links, while bulk data transfers used cost-effective broadband links. Automatic failover was configured to switch to backup LTE or broadband links within 5 seconds of a primary link failure.
We also deployed cybersecurity measures including next-generation firewall policies, IPS, and web filtering at each branch. Centralized management was achieved using FortiManager and Cisco vManage, providing the IT team with a single pane of glass for monitoring and policy enforcement. For cloud connectivity, we established direct peering with AWS and Azure via hybrid cloud connections, reducing latency to cloud applications by 60%. Additionally, we integrated server and storage resources at the head office with Synology NAS devices for local caching at larger branches, ensuring fast access to frequently used data. The entire deployment was completed in 12 weeks, with minimal disruption to business operations.
04
Results & ROI
Post-implementation, the enterprise achieved a 70% reduction in network latency for critical applications, with average latency dropping from 250ms to under 40ms. Application performance improved significantly, with Office 365 response times decreasing by 80%. The automatic failover mechanism ensured 99.99% uptime across all branch offices, eliminating prolonged outages. The company reported zero downtime during the first six months after deployment, compared to three major outages in the previous year. Bandwidth costs were reduced by 30% by utilizing cost-effective broadband links for non-critical traffic, while MPLS was retained only for sensitive data.
The centralized management platform reduced IT troubleshooting time by 60%, as the team could now identify and resolve issues remotely. Security incidents dropped by 90% due to consistent firewall policies and real-time threat intelligence. The enterprise also achieved a return on investment within 8 months, primarily from reduced downtime costs and bandwidth savings. Employee productivity increased by 25% due to faster application access and reliable VoIP and video conferencing. The solution also provided scalability to easily onboard new branch offices in under a week, supporting the company's expansion plans in Eastern Indonesia. Overall, the multi-site network transformation enabled the enterprise to accelerate its digital transformation and gain a competitive edge in the retail and distribution sector.