EnterpriseConfigSchedule a Consultation
Back to services

HA enterprise architecture

Enterprise Network Design

A strong enterprise network needs more than switches and firewalls. It needs clear routing boundaries, redundant paths, secure remote access, identity integration, cloud connectivity, and operational visibility from day one.

Fortinet HA edge with dual ISP, SD-WAN, IPS, VPN, and centralized logging

Cisco campus switching with redundant core, distribution, and access layers

Hybrid identity using Azure Entra ID, MFA, local domain controllers, and conditional access

Secure site-to-site VPN, SSL VPN, IPsec remote access, Azure, and branch connectivity

Reference HA Design

Full HA enterprise network layout.

A practical layout for a medium enterprise with resilient internet, secure segmentation, hybrid identity, and cloud-ready routing.

Enterprise network architecture design with FortiGate HA, switching layers, access networks, and management servicesEXTERNALNETWORKSPERIMETER / EDGECORE LAYERDISTRIBUTIONLAYERACCESSLAYERMANAGEMENT& SERVICESInternetISP AInternetISP BCloud ServicesMicrosoft 365 / AWS / AzureSaaS / BusinessBusiness ApplicationsPublic IPsPublic IPsFortiGate 1800FHA PrimaryFortiGate 1800FHA SecondaryHA LinkCore Switch 01 (L3, Stack/VSX)Core Switch 02 (L3, Stack/VSX)MLAG / LACP10/25/40/100GDistribution 01 (Stack)Distribution 02 (Stack)Distribution 03 (Stack)Distribution 04 (Stack)L3 Uplinks10/25/40/100GL2 / L3 Uplinks1/10/25GUSERSVLAN 10VOICEVLAN 20SERVERSVLAN 30WIRELESSVLAN 40FortiManagerCentralized ManagementFortiAnalyzerLogging & ReportingFortiNACNetwork Access ControlRADIUS / AD / LDAPAuthenticationSyslog / NTP / DNSInfrastructure ServicesBackup / MonitoringAvailability & AlertsDESIGN PRINCIPLESHigh AvailabilityRedundancyScalabilitySecurity SegmentationPerformanceResilienceSECURITY ZONESWANDMZLANManagementCORE FUNCTIONSHigh-speed SwitchingInter-VLAN RoutingRedundant UplinksFast ConvergenceDISTRIBUTION FUNCTIONSPolicy EnforcementRoute SummarizationInter-VLAN FilteringHigh AvailabilityACCESS FUNCTIONSEndpoint ConnectivityVLAN Assignment802.1X / NACPoE for IP Phones / APsMANAGEMENT NETWORKOut-of-Band ManagementMonitoring & LoggingAuthentication ServicesBackup & ReportingLINK LEGEND10/25/40/100G FiberHA / SynchronizationAccess / CopperManagement NetworkInternet / WANKEY BENEFITSSecure by DesignHigh AvailabilityScalable ArchitectureOperational Efficiency
Layered enterprise network design concept with external networks, FortiGate HA edge security, redundant core and distribution switching, access VLANs, user/voice/server/wireless endpoints, management services, design principles, and link legends.
1

Internet + ISPs

Dual ISP circuits, public DNS, DDoS-aware routing, and monitored failover.

2

Fortinet HA Edge

FortiGate HA pair, SD-WAN rules, IPS, web filtering, SSL VPN, IPsec VPN, and FortiAnalyzer visibility.

3

Cisco Core

Redundant Catalyst or Nexus core with HSRP/VRRP, routed uplinks, VLAN gateways, and fast convergence.

4

Secure Access

Cisco access switching, 802.1X, ISE-ready NAC, guest networks, voice, printers, and IoT segmentation.

5

Identity + DC

Local Active Directory domain controllers, DNS, DHCP, Azure Entra ID sync, MFA, and policy-based access.

6

Cloud + Branch

Azure VPN Gateway or ExpressRoute, branch IPsec tunnels, SD-WAN overlays, and cloud workload routes.

Traffic flow

Users
Cisco Access
Cisco Core
Fortinet HA
VPN / Cloud
Apps + DC

Sample network designs

Practical patterns for real environments.

These examples show how the same principles can be shaped for a single office, branch network, hybrid cloud, or remote access requirement.

Single-site HA office

Best for a headquarters or main office where internet, switching, servers, and identity services must stay available during device or circuit failure.

  • Dual ISP links into a FortiGate HA pair with SD-WAN health checks and monitored failover.
  • Cisco collapsed core using redundant switches, LACP uplinks, HSRP/VRRP gateways, and separate management access.
  • Local domain controllers, DNS, DHCP failover, file/application servers, backup storage, and UPS-backed server switching.

Head office plus branches

Best for distributed companies that need predictable branch connectivity, secure local breakout, and central visibility.

  • Hub FortiGate HA pair at headquarters with branch FortiGate or Cisco edge devices connected by IPsec or SD-WAN overlays.
  • Central route summarization, branch VLAN templates, guest networks, printer networks, and local emergency internet breakout.
  • FortiManager templates and documented onboarding standards so every branch is built the same way.

Hybrid cloud network

Best for businesses running local servers while extending workloads, identity, backup, or applications into Microsoft Azure.

  • Azure VPN Gateway, Virtual WAN, or ExpressRoute connected to the Fortinet edge with clear route ownership.
  • Azure Entra ID, local Active Directory, domain controller placement, DNS forwarding, and conditional access alignment.
  • Separate cloud subnets for application, database, management, backup, and private endpoint traffic.

Secure remote access design

Best when engineers, staff, and vendors need access from outside while keeping internal systems protected.

  • FortiGate SSL VPN or IPsec VPN with Azure Entra ID SAML, MFA, named user groups, and restricted portal access.
  • Separate access profiles for employees, administrators, vendors, and emergency support.
  • Jump hosts, management VLANs, session logging, and deny-by-default firewall rules for sensitive servers.

Design principles

A good enterprise design is predictable under failure and simple enough for the operations team to understand. The design should reduce hidden dependencies and make every critical path visible.

  • Build redundancy in pairs: firewalls, switches, WAN links, power, domain controllers, DNS, DHCP, and backup paths.
  • Keep routing boundaries clear with summarization, documented default gateways, and controlled redistribution.
  • Separate user, server, voice, guest, management, backup, IoT, OT, and cloud traffic into intentional zones.
  • Prefer least privilege access: users reach applications, administrators reach management planes, and vendors reach only approved targets.
  • Document normal traffic flows, failure modes, recovery steps, and ownership before the design goes live.

Server and data center design factors

Server networks need stable addressing, clean east-west controls, reliable backup paths, and protected management access. They should also be designed around the applications they host.

  • Dedicated server VLANs or subnets for domain controllers, application servers, databases, backup, monitoring, and management.
  • Redundant server access switches, dual-homed hypervisors, LACP port channels, and separate out-of-band management where possible.
  • Firewall policies between user networks and server networks so only required application ports are allowed.
  • Resilient DNS, DHCP, NTP, certificate services, backup repositories, and monitoring placed outside single points of failure.
  • Capacity planning for virtualization, storage, east-west traffic, backup windows, internet breakout, and future cloud migration.

Fortinet edge and VPN design

The firewall edge is designed as a high-availability security control point, not just an internet gateway. A FortiGate HA pair can terminate dual internet circuits, run SD-WAN policies, inspect traffic, publish services safely, and provide remote access.

  • Active-passive or active-active FortiGate HA depending on throughput, session behavior, and licensing needs.
  • SSL VPN or IPsec remote access with Azure Entra ID SAML, MFA, user groups, and least-privilege portal access.
  • Site-to-site IPsec VPNs for branches, partners, Azure, and disaster recovery locations.
  • FortiManager and FortiAnalyzer for consistent policy, configuration history, reporting, and incident visibility.

Cisco campus foundation

The switching design keeps the campus predictable: redundant core or collapsed-core switching, routed uplinks where appropriate, clear VLAN boundaries, and access policies that are easy to operate.

  • Cisco Catalyst or Nexus core/distribution with HSRP, VRRP, StackWise Virtual, vPC, or equivalent HA patterns.
  • Access layer segmentation for users, servers, voice, printers, wireless, guest, OT, and management networks.
  • Cisco ISE-ready 802.1X and MAC authentication for identity-aware wired and wireless access.
  • QoS for voice, video, business applications, and WAN-sensitive traffic.

Hybrid identity and access

Identity ties the network together. Local domain controllers keep core services close to users, while Azure Entra ID adds cloud identity, SSO, MFA, and conditional access for remote and SaaS workflows.

  • Local Active Directory, DNS, DHCP, NTP, and certificate services placed on resilient server networks.
  • Azure Entra ID Connect or cloud sync for hybrid identity and consistent user lifecycle management.
  • MFA and conditional access for VPN, administrator access, SaaS, and privileged workflows.
  • Admin separation using management VLANs, jump hosts, role-based access, and audited changes.

Cloud, branch, and resilience

Cloud and remote offices are treated as first-class network locations. Routing, segmentation, monitoring, and failover are designed before migration or expansion begins.

  • Azure VPN Gateway, Virtual WAN, or ExpressRoute planning based on latency, cost, and availability requirements.
  • Branch FortiGate or Cisco edge designs with SD-WAN, local breakout, and central policy control.
  • Backup internet, LTE/5G options, dynamic routing, and documented failover testing.
  • Monitoring for firewall health, WAN quality, switch stack state, VPN status, and key application paths.

Technology stack

FortiGateFortiManagerFortiAnalyzerCisco CatalystCisco NexusCisco ISEAzure Entra IDActive DirectoryAzure VPN GatewayExpressRoute

Next step

Discuss a design for your environment.

Share your current topology, pain points, cloud plans, and security goals. EnterpriseConfig can turn that into a practical design and implementation path.

Contact EnterpriseConfig