14 Sept 2026 · 8 min read

When did your backup link last carry the plant?

scada · edge · practice

Pick one of your remote sites: a pumping station, a substation, a wellpad two hours' drive from the control room. It almost certainly has a second way out. There is a 4G router on a DIN rail next to the fibre box, installed after the last long outage, and its SIM has been paid for every month since.

When did that router last carry the SCADA traffic? The question isn't when it was installed, or whether its light is green. It's when it last actually carried the plant, and how long the switchover took.

Most people can't answer that, and it isn't carelessness. Proving a backup link works means pulling the primary on purpose, which takes an outage window, somebody on site and a good reason to take the risk. So the test waits for a real fault, and a real fault is the worst possible moment to find out the SIM was cancelled in March.

A classic WAN treats a site's links as fixed facts. The fibre carries everything and the backup waits. SD-WAN, short for software-defined wide-area network, treats them as a pool instead. A box at the edge of the site sends small test packets down every link all the time, measuring delay, jitter and loss, and it moves traffic according to rules somebody wrote.

On a Fortinet FortiGate the default check runs every half second, and a link is declared dead after five misses in a row, so a failed link is noticed in about two and a half seconds. Its routes are withdrawn, and they come back once it passes again. So the backup is no longer waiting for a fault. It is tested around sixty million times a year, and anyone with access to the manager can see its state today, not on the day of the next fault.

ONE YEAR OF THE BACKUP LINK

classic WANcarried the plant: unknown
?
installed
under SD-WANchecked ~60 million times
every half second, all year
JanAprJulOctDec
The same router, the same SIM, the same year. What changed is not the link but whether anybody can say it works.

That is the first thing SD-WAN gives a plant, and I'd argue it is worth more than everything else put together: evidence about the links you already pay for. Cisco, Palo Alto Networks and HPE Aruba sell the same idea. I'm using Fortinet here because its rugged hardware and its documentation make the examples concrete.

The WAN becomes a rule, not a circuit

The second change is less obvious. Once every link is measured, you stop assigning purposes to circuits and start writing rules about traffic.

A remote site sends very different things upstream. Telemetry to the control room is small and constant, and it must never stop. A vendor's support session needs a clean link for an hour. Camera footage is heavy and can wait, and patches are heavier and can wait longer. On a classic WAN all of it shares the fibre until the fibre fails, then all of it lands on the 4G together, and the telemetry ends up fighting a camera stream for the same narrow link.

With SD-WAN each kind of traffic gets its own rule. Telemetry takes whichever link meets its delay target and can fall back through every link the site has. Cameras stay on fibre or broadband and are never allowed onto the metered cellular link. Patches wait for the cheap one. Fortinet's OT security service adds recognition for Modbus, DNP3, IEC 60870-5-104, IEC 61850, S7 and EtherNet/IP, so a rule can say DNP3 to the control room rather than naming a port number and a subnet.

WHICH TRAFFIC MAY USE WHICH LINK

fibrebroadband5G, meteredtelemetry to the control room1st2nd3rdvendor support session1st2nd3rdcamera footage1st2nd✕ neverpatches and updates2nd1st✕ never
Each row is one rule. The circuits did not change; what changed is that every kind of traffic now has a written order of links, and a list of links it may never touch.

Two details are worth knowing before you promise anybody this. The OT protocol signatures are switched off by default, and they are a separate subscription, sold on its own rather than inside the usual security bundle. SD-WAN itself needs no extra licence on any FortiGate.

Because the paths are tunnels you define, plant traffic and office traffic can also travel in separate encrypted tunnels across the WAN. The link between a site's control zone and the control room becomes a path somebody designed, not whatever the routing table happened to allow. That is the conduit idea from IEC 62443, with a box that can hold it at every site and not only at head office.

Switching on a site without a network engineer in it

This is where it starts to matter if you have thirty sites rather than three. The person who installs a box at a remote pumping station is usually an instrument technician or an electrician, not a firewall engineer, and the old way asked them to type configuration into a console with somebody talking them through it on the phone.

Zero-touch provisioning removes that job. The box is registered to your account by serial number before it ships. On site it gets power and any internet connection, calls home with its serial number, learns where your FortiManager is, connects, and pulls the full configuration written for that site. The rugged FortiGate range is rated from −40 to 75 °C and comes in versions with 4G or 5G built in, so that first internet connection can be the cellular link itself.

WHAT HAPPENS WHEN A BOX ARRIVES

IN THE OFFICEON SITE
1serial number registered to your account before the box ships
2the site's configuration written, reviewed, and left waiting
3a technician connects power and any internet link
4the box calls home with its serial and learns where the manager is
5it connects and pulls the configuration written for that site
Four of the five steps happen without anybody touching the box, and two of them happen before it has even shipped.

The technician's job is cabling. Everything that makes the box belong to that site was decided in the office, reviewed, and was already waiting for it.

Why the network is going the way SCADA configuration went

If this sounds familiar, it should. Plants are making the same move with SCADA itself: stop clicking configuration into each machine, and keep it as files you can review, version and apply to a whole fleet at once. I've written about what that looks like for gateways. SD-WAN is the network layer catching up.

The tooling is maintained rather than promised. Fortinet publishes its own Terraform providers and Ansible collections for both the firewall and its manager, all of them updated in the last two months, and the firewall itself has a REST API. FortiManager can generate the tunnels and routing for every hub and branch from one definition. A site stops being a box somebody configured in 2023 and becomes a row in a table, holding its name, its addresses, the links it has and the template it follows.

ONE CHANGE, THIRTY SITES

sites/template.tf links = [fibre, 5g]+ cameras: never on 5gPortoTampereValenciaLeipzigRotterdam+25 morereviewed once
The old way was thirty logins, done one at a time, by whoever had time that week. This way it is one change, read by a second person, arriving at every site identically.

I think this becomes the default rather than a fashion, and the reason is arithmetic. Sites keep being added, each one now has two or three links instead of one, and every link carries a policy, a health check and a cost. Past a couple of dozen sites nobody keeps that consistent by hand, and the drift shows up the way drift always does: the site set up differently is the one that fails differently. Once the network is a file, is every site configured the same way is answered by a diff instead of a site visit.

The bill moves when the traffic moves

This is the part that rarely makes the brochure. Once links are a pool, cost becomes a routing decision, and a machine makes routing decisions twice a second.

The upside is large. TeleGeography's pricing research put the median 100 Mbps MPLS port at 7.3 times the price of comparable business broadband, and the gap ran from under three times in one city to over twenty in another. SD-WAN is how an operator moves most of its traffic onto broadband without giving up the behaviour MPLS was bought for. A FortiGate can be told what each link costs and will pick the cheapest one that still meets a traffic class's target.

The downside is the metered link. A failover rule that doesn't tell traffic apart will move camera streams and a patch download onto a SIM priced by the gigabyte, and nobody notices until the invoice arrives.

ILLUSTRATIVE · DATA USED ON THE 5G LINK, ONE MONTH

fibre cut →0 GB100 GB200 GBday 1day 10day 20day 30no traffic rules~236 GBcameras kept off~5 GB
Illustrative numbers. The same three-day fibre cut, the same site; the difference is whether anybody wrote down what may not travel over the expensive link.

So managing the bill comes down to three habits. Give every link a cost. Keep the expensive links on a short list of traffic that is allowed to use them. And alert on how much data each link has carried, not only on whether it is up, because an expensive link that is up and busy looks perfectly healthy.

The licences deserve the same attention. Under FortiFlex, Fortinet's usage-based licensing, points are consumed daily, and for hardware they start being consumed the day the entitlement is created, even if the box is still in its crate. Create entitlements when the site is ready, not when the purchase order clears.

Where it falls short

I'd rather you hear the limits here than from your first outage.

It shortens the outage but does not recover what the outage cost. If both links leave the site through the same trench, or the router simply loses power, the readings from that window are gone unless the site kept its own copy. That is a separate decision about where the first durable write happens, and SD-WAN does not make it for you.

TWO FIXES, NOT ONE

SD-WANhow longthe site isunreachablesite copywhetherthe readingssurvivean outagenobodynotices
Either circle on its own leaves you with a problem the other one solves. Only the overlap turns a cut link into a non-event.

The overlay belongs to one vendor. In practice every site runs the same brand of box, and leaving means replacing every box. That is a reasonable trade for most operators, but it is worth making knowingly.

The manager becomes a dependency for change. A site keeps forwarding on the configuration it already has if the central manager is unreachable, but nobody can push a new rule until it is back.

Every site now has a firewall with firmware, and its patch cycle is one more thing plant change control has to own. Fortinet says FortiOS 7.6 is certified to IEC 62443-4-2 at security level 4. That is a statement about the product, not about how yours is configured, and certified is not secure covers the gap.

What to check this week

Pick your most remote site and ask two questions. When did its backup link last carry the SCADA traffic? And what would travel over that link if the primary died tonight? If the answers are we assume it works and everything, you already know where the first rule goes, and you know it before anyone has priced a box.

Keep reading

Newsletter

New essays, by email.

SCADA, cloud, AI, and the plant floor — a short email when something new is published. No noise, unsubscribe anytime.