Multi-Site Enterprise Network Topology Architecture (HO, Warehouse Pemuda & Branch Site 3)

March 10, 2026

Designing a resilient enterprise network across multiple sites requires custom topology planning tailored for Head Office (HO) security, remote Warehouse operational reliability, and lightweight Branch Site surveillance.

1. Head Office (HO) Architecture

Head Office is the central security and routing hub handling high user density and strict perimeter security:

  • Edge NGFW: Fortinet FortiGate 71G
  • Dual WAN Link:
    • WAN 1: Whiz (Primary ISP)
    • WAN 2: Lintasarta (Secondary ISP / Failover)
  • Direct Connections to FortiGate (HO):
    • DVR CCTV System: Connected directly to FortiGate interface for dedicated security surveillance isolation and remote viewing ACLs.
    • Ruijie PoE Switch: Directly connected to FortiGate, powering 4x Ruijie Access Points (AP1, AP2, AP3, AP4).
    • TP-Link 16-Port Manageable Switch #1: Connected to FortiGate for floor distribution.
    • TP-Link 16-Port Manageable Switch #2: Trunked from Switch #1 for additional expansion.
[ Head Office (HO) Topology ] [ Internet ] ┌────────────┴────────────┐ [ WAN 1: Whiz ] [ WAN 2: Lintasarta ] └────────────┬────────────┘ │ (SD-WAN Load Balance & Failover) [ FortiGate 71G (HO NGFW) ] │ (Web Filter, Security ACL, QoS Shaper) ├─────────────────────────┬────────────────────────┐ │ (Direct DVR Interface) │ (VLAN Trunk / PoE) │ (VLAN Trunk) ▼ ▼ ▼ [ DVR CCTV HO ] [ Ruijie PoE Switch ] [ TP-Link 16P Switch #1 ] ├── AP 1 (Ruijie) (Floor 1 Workstations) ├── AP 2 (Ruijie) │ ├── AP 3 (Ruijie) │ (Trunk Link) └── AP 4 (Ruijie) ▼ [ TP-Link 16P Switch #2 ] (Floor 2 Workstations)

2. Warehouse Pemuda Site Architecture

The Warehouse Pemuda facility is engineered for high throughput, local network stability, and dedicated surveillance logging using MikroTik RouterOS:

  • Primary Gateway Router: MikroTik RB5009
  • WAN Link: Whiz (Primary ISP)
  • Direct Connections to MikroTik RB5009:
    • DVR CCTV System: Connected directly to dedicated MikroTik port with strict isolation rules and port-forwarding/VPN access.
    • TP-Link 8-Port Switch: Directly connected to MikroTik RB5009.
      • Wireless Coverage: AP1 & AP2 connected to the 8-Port Switch.
      • Warehouse Office Distribution: TP-Link 16-Port Manageable Switch connected to the 8-Port Switch, supplying connectivity for warehouse office PCs, barcode scanners, and inventory workstations.
[ Warehouse Pemuda Site Topology ] [ Internet ] │ [ WAN 1: Whiz ] │ [ MikroTik RB5009 ] │ (Gateway / Routing) ├──────────────────────────────────────┐ │ (Direct Port) │ ▼ ▼ [ DVR CCTV Warehouse ] [ TP-Link 8-Port Switch ] ┌──────────────────┼──────────────────┐ ▼ ▼ ▼ [ AP 1 ] [ AP 2 ] [ TP-Link 16P Switch ] (Office & Scanners)

3. Branch Site 3 Architecture

Branch Site 3 is configured as a compact remote branch designed for essential office connectivity and dedicated 6-channel IP surveillance:

  • WAN Link: ISP Modem Gateway
  • Distribution & Surveillance:
    • TP-Link 8-Port Switch: Connected directly to ISP Modem.
    • 6-Channel NVR (Network Video Recorder): Connected to the 8-Port Switch for local IP camera stream management and remote viewing.
[ Branch Site 3 Topology ] [ Internet ] │ [ ISP Modem ] │ [ TP-Link 8-Port Switch ] ┌─────────────────┴─────────────────┐ ▼ ▼ [ NVR 6-Channel ] [ Branch Office PCs / AP ] (CCTV IP Cameras)

4. Key Technical Implementations

A. Dedicated Surveillance Isolation (DVR & NVR)

Directly attaching DVR/NVR systems to FortiGate (HO), MikroTik (Warehouse Pemuda), and 8-Port Switch (Site 3) allows:

  • Traffic Isolation: Separating high-volume CCTV IP stream data from office workstation VLANs.
  • Secure Remote Access: Restricting DVR/NVR access to authorized management IPs and encrypted VPN tunnels.

B. VLAN Traffic Isolation

Segmented office and warehouse subnets into distinct virtual networks to isolate traffic and enforce security boundaries:

  • Management: Network infrastructure devices, switch management, and AP controllers.
  • Corporate Staff & Office: Internal PCs, workstation laptops, and handheld scanners.
  • Guest Wi-Fi: Isolated direct-to-internet network for visitors.

C. SD-WAN Dual-WAN Failover & Load Balancing (HO)

  • Load Balancing: Configured FortiGate SD-WAN interfaces with traffic distribution rules across primary and secondary ISPs.
  • Automated Failover: Continuous WAN health checks trigger instant, seamless failover to Lintasarta if Whiz experiences latency or link drops.

D. Web Filtering & Security ACL Rules

Enforced Application Control and Web Filter Security Profiles on FortiGate firewall policies:

  • Access Control Lists (ACL): Restricted non-work related site categories (Social Media, Streaming, Gaming, Gambling, P2P).
  • Scheduled Exemption Rules: Policy rules configured for flexible access during non-working hours.

E. Bandwidth Management & QoS Traffic Shaping

Implemented Traffic Shaper policies on FortiGate (HO) and Simple Queues on MikroTik RB5009 (Warehouse):

  • Priority Bandwidth Allocation: Guaranteed bandwidth for critical SaaS workflows (Microsoft 365, Teams, Exchange) and enterprise ERP.
  • Rate Limiting: Enforced bandwidth caps on Guest networks and non-essential devices.
LinkedIn
GitHub