Multiple Branches, Multiple Challenges
Any organization operating more than one office knows that branch connectivity is far more complex than it appears. Employees need reliable access to ERP systems from remote sites. IT teams need to manage infrastructure without visiting every location. Video conferences stall or drop at the worst moments.
The question that surfaces consistently is: "Should we use VPN Site-to-Site or SD-WAN?"
Both technologies connect branches — but they operate differently, scale differently, and serve different organizational profiles. Choosing the wrong one can mean a network that is difficult to manage, costs more than expected, or simply cannot keep up with the business.
What Is VPN Site-to-Site?
VPN Site-to-Site creates an encrypted tunnel between two network devices — typically firewalls or routers at the HQ and branch — using the public internet as the underlying transport.
Key characteristics:
- Encrypted Tunnel: All traffic is encrypted in transit, protecting against interception
- Internet-based: No private line required — runs on existing internet connections
- Static Configuration: Routes and policies are configured manually, device by device
- Low upfront cost: No MPLS or Private Line fees — the branch internet connection is the only cost
- Complexity scales with branch count: Managing VPN configurations becomes exponentially harder as branches are added
What Is SD-WAN for Multi-Branch?
SD-WAN uses software intelligence to manage multiple WAN connections simultaneously — MPLS, DIA, or 4G/5G — routing each traffic flow to the optimal path automatically.
In a multi-branch context, SD-WAN delivers:
- Zero-Touch Provisioning: Open a new branch by plugging in the device and powering on — configuration is pulled automatically from the cloud
- Application-Aware Routing: VoIP goes over MPLS; YouTube goes over DIA — automatically, without manual rules
- Central Dashboard: Every branch visible from a single pane of glass — traffic, health status, and alerts in real time
- Dynamic Failover: If the primary link fails, traffic switches to the backup path within seconds — automatically
- Built-in Security: NGFW, IPS, and URL filtering integrated in one device — no separate firewall needed at each site
VPN Site-to-Site vs. SD-WAN — Direct Comparison

| VPN Site-to-Site | SD-WAN | |
|---|---|---|
| Underlay | Internet only | MPLS + DIA + 4G/5G combined |
| Deployment | Manual, site by site | Zero-Touch Provisioning |
| Failover | Manual or scripted | Automatic (seconds) |
| Application Awareness | None | Native |
| Central Management | No unified dashboard | Single dashboard |
| Security | Encrypted tunnel only | NGFW + IPS built-in |
| Complexity as branches grow | Very high | Low — scales easily |
| Upfront cost | Lower | Higher |
| Best for number of branches | 2–5 branches | 5+ branches |
| SLA | Depends on ISP | 99.95% (KIRZ) |
When to Choose VPN Site-to-Site
VPN Site-to-Site remains the right choice in the following situations:
1. Small organizations with 2–3 branches When the branch count is low, VPN complexity remains manageable and the cost advantage over SD-WAN is significant.
2. Limited budget VPN Site-to-Site runs on existing internet connections. Hardware and licensing costs are minimal compared to SD-WAN deployment.
3. Simple, low-volume traffic If most traffic consists of access to a file server or a handful of internal applications, VPN provides sufficient performance at minimal cost.
4. Backup for a Private Line VPN over internet is an efficient and cost-effective failover option when the primary MPLS or Private Line link experiences issues.
When to Choose SD-WAN
1. Five or more branches As the branch count grows, managing individual VPN configurations becomes a significant IT burden. SD-WAN manages every site from one dashboard.
2. Multiple cloud applications in use Microsoft 365, Salesforce, Zoom — SD-WAN recognizes these applications and routes their traffic directly to the cloud without backhauling through HQ, reducing latency and improving user experience.
3. High uptime requirements SD-WAN supports multiple underlay connections simultaneously, with automatic failover in under one second. End users experience no disruption when a link degrades.
4. Small IT team managing many sites Zero-Touch Provisioning and a central dashboard allow a small IT team to deploy, monitor, and troubleshoot every branch remotely — no site visits required.
5. Full traffic visibility needed See every application, every user, every branch in real time — not just link up/down status.
3-Year TCO Comparison: VPN vs. SD-WAN (5 Branches)

| Item | VPN Site-to-Site | SD-WAN |
|---|---|---|
| Hardware (Firewall/Router) | THB 150,000 | THB 300,000 |
| License / Subscription | THB 0 | THB 180,000 |
| Internet (5 branches × 3 years) | THB 540,000 | THB 540,000 |
| IT Management Cost | High (manual) | Low (automated) |
| Downtime Cost | High (no auto-failover) | Low |
| Approximate Total | ~THB 800,000+ | ~THB 1,100,000 |
Note: SD-WAN carries a higher upfront cost in year one. However, when IT management overhead and reduced downtime are included, the gap narrows significantly in years two and three — and for organizations with complex traffic or high uptime requirements, the operational advantage of SD-WAN typically outweighs the cost difference.
KIRZ SD-WAN — Built for Multi-Branch Organizations

KIRZ delivers SD-WAN on Fortinet and Cisco Viptela platforms, supporting:
- Hub-and-Spoke: HQ as the central hub; branches connect through it
- Full Mesh: Every branch connects directly to every other — lower latency for branch-to-branch traffic
- Hybrid: A combination of both topologies, matched to the traffic pattern
Underlay support: KIRZ SR-MPLS + DIA + 4G/5G
Security built-in: NGFW, IPS, URL Filtering
SLA: 99.95% | 24/7 NOC
KIRZ's Presale team is available to design a WAN architecture matched to your branch count, traffic profile, and budget.
Conclusion — Choose Based on Branch Count and Complexity
VPN Site-to-Site is the right fit for small organizations with 2–5 branches, limited budget, and straightforward traffic requirements.
SD-WAN is the right fit for organizations with 5+ branches, cloud-heavy workloads, high uptime requirements, or a small IT team managing a growing network.
If you are unsure: Start with VPN, then migrate to SD-WAN as branches grow or when the IT team needs centralized visibility and automated management.
Ready to design the right WAN for your multi-branch organization?
Contact KIRZ's specialists at kirz.com or call 02-770-9770..