Connecting multiple sites so every office works as one
There are three ways to connect multiple sites: a VPN between the firewalls at each office, a managed SD-WAN, or a dedicated carrier line. For most companies with two to five sites, firewall-to-firewall VPN does the job well; with many branches, voice traffic or business-critical applications, SD-WAN earns its cost. The decision is not driven by a product catalogue but by what is shared and how much an outage hurts.
First: what actually needs to travel between offices
Before looking at hardware, write down what will cross between sites. Sharing a folder is not the same as running the ERP at head office with thirty people working against it from another region.
- Shared files and network folders
- Business applications hosted at head office or in the cloud
- IP telephony and video calls, which suffer badly from latency
- Printing and scanning to central systems
- Backups from branches to the main site
- Cameras, access control and time tracking
The three options and when each fits
Firewall-to-firewall VPN is the most common and the most sensible choice in most cases: each site has its own internet line and a permanent encrypted tunnel to the others. It is affordable, quick to set up and, with decent firewalls at both ends, it is stable.
SD-WAN goes further: it uses several lines at once, steers traffic by type and, if one line degrades, moves voice to another without dropping the call. It pays off when there are several branches, IP telephony and applications that cannot tolerate interruptions.
A dedicated point-to-point carrier line gives guaranteed bandwidth and very stable latency, but it costs considerably more and takes weeks to install. It makes sense in specific cases: nearby sites with heavy traffic, or systems that cannot tolerate variability.
The failures we see most in multi-site networks
Nearly every incident we handle at multi-office companies repeats. The most common: both sites use the same IP address range, so tunnels refuse to come up or behave in ways nobody can explain. Next: a single internet line with no backup at a branch that invoicing depends on. And third: no monitoring at all, so nobody knows the tunnel has been down for three days until someone cannot open a file.
All three are avoided with planning: coherent addressing from day one, a backup line at critical sites, and central monitoring with automatic alerts.
Managing every site from one place
With several offices, what makes the difference is not the tunnel technology but how it is administered. With managed equipment and a central console you apply the same security policies everywhere, see the state of each line, and roll out a change to all sites at once without travelling.
That same console is what lets you open a new branch in days rather than weeks: the configuration is already defined, you only install the device and adopt it.
How we do it at iDeo Networks
We design and maintain multi-site networks for companies across Spain, including the Canary and Balearic Islands, Ceuta and Melilla, where connectivity has its own quirks worth planning for from the start. We begin with an inventory of what sits in each office and with the addressing scheme, before proposing any hardware.
We also work with international companies whose Spanish branch has to fit into the group’s corporate network.
Related services
Opening a new site, or running several that are poorly connected?
We review what you have at each office and propose the way of linking them that fits your real usage.
Talk to an engineer