Build // Networking & SD-WAN

Networking Designed to the Requirement, Then Built to the Design

Multi-site connectivity, next-generation firewalls, Wi-Fi 6, and unified communications for Saudi enterprises. Every engagement establishes the architecture first and selects hardware against it, so the design answers your requirements rather than a product line.

Reference Architecture
EDGE
Branch sitesRemote usersField devices
TRANSPORT
Secure SD-WANDual carrierApp-aware routing
SECURITY
NGFWZTNASegmentationIPS
CORE
Data centerCloud workloadsApplications
Capabilities

What We Design and Build

Six capability areas. Most engagements combine three or four.

SD-WAN & Branch Connectivity

/ 01
Multi-site, centrally governed

Branch links that fail over without user impact, application-aware routing that prioritizes business-critical traffic, and central policy control across every site. Our engineers hold the Fortinet Secure SD-WAN specialization.

Secure SD-WANApplication-aware routingAutomatic failoverZero-touch branch provisioningCentral policy managementLink performance reporting

Next-Generation Firewalls

/ 02
Built to the full perimeter

The modern perimeter spans remote workers, branch offices, and cloud workloads. Firewall architecture is designed to that full scope and operated under Fortinet Expert-level credentials.

NGFW deploymentIPS / IDSApplication controlSSL inspectionSegmentationHigh availability clustering

Enterprise Wireless & Wi-Fi 6

/ 03
Engineered for density

Coverage is straightforward. Density is the harder problem: a warehouse floor, a lecture hall, an open-plan headquarters at peak occupancy. Every deployment begins with an RF survey and closes with heat-map validation.

Predictive and on-site RF surveyWi-Fi 6 / 6E deploymentGuest and BYOD onboardingCaptive portalHeat-map validationOngoing RF optimization

LAN & Data Center Switching

/ 04
Resilience at the foundation

Core, distribution, and access layers designed to absorb a switch failure without an unplanned outage. Structured cabling, redundant uplinks, and as-built topology documentation maintained against the physical estate.

Core and access switchingRedundant topology designStructured cablingVLAN and QoS architectureStacking and MLAGAs-built documentation

Unified Communications & Voice

/ 05
Quality decided at the network layer

IP telephony, contact center, and collaboration platforms, integrated with the network beneath them. Voice quality is determined at the network layer, and the design treats it accordingly.

IP telephonyContact centerMicrosoft Teams voice integrationSIP trunkingQoS for voiceCall quality reporting

Zero-Trust Network Access

/ 06
Per-application, continuously verified

Traditional VPN grants broad network access on successful authentication. ZTNA grants access to a single application, verified continuously against user and device posture. The two represent materially different security models.

ZTNA deploymentPer-application access policyDevice posture checksIdentity integrationContinuous verificationVPN migration path
Delivery Model

Five Phases, and What You Get From Each

Each phase closes with a deliverable you own.

01
Week 1–2

Discover

We map the estate as it currently runs, which frequently differs from the documented version. Traffic patterns, application dependencies, contract end dates, and any legacy systems carrying undocumented behaviour.

You get: Current-state assessment and dependency map
02
Week 2–4

Design

Architecture before product. We design the topology against your requirements — sites, bandwidth, failover tolerance, compliance obligations — and only then decide what hardware serves it. You approve the design before anything is quoted.

You get: Signed-off architecture and bill of materials
03
Week 4–6

Pilot

One site, or one segment, running the new design in parallel with the existing one. Issues surface at a location selected for low operational impact, and are resolved before the design reaches the wider estate.

You get: Validated pilot with measured results
04
Ongoing

Rollout

Site by site, each with a documented rollback path. Cutover windows are agreed against your operational calendar, and every site is validated before the next one begins.

You get: Phased cutover, zero unplanned outage target
05
Close

Handover

As-built documentation maintained against the physical estate, your team trained on the platform, and an agreed support path. Ongoing operations remain a separate decision you make freely.

You get: As-built docs, training, and support model
Platforms

What We Build On

Partnerships give our architects range and direct escalation paths. Your requirements determine the architecture.

FortinetExpert-level partner. Secure SD-WAN and Secure Networking Firewall specializations.
CiscoEnterprise switching, routing, and collaboration platforms.
Hewlett Packard EnterpriseCampus and data center networking, wireless infrastructure.
AvayaUnified communications and contact center platforms.

ITBuilders holds no exclusive vendor agreements. Full partner roster on the partners page.

Case Pattern

What This Looks Like in Practice

Illustrative Pattern — Not a Client Engagement

Multi-Site Retail Group, Central & Eastern Province

The Problem

Branch links managed device by device. Point-of-sale traffic competing with everything else on the same pipe. A carrier outage at one site meant that site closed until the line came back.

The Approach

Discovery mapped actual application dependencies against the documented ones. SD-WAN design with dual carriers, application-aware routing prioritizing payment traffic, and central policy. Pilot at two sites for three weeks before any wider rollout.

The Outcome

Carrier failure at a single site now fails over without closing the store. Policy changes deploy centrally rather than per device. Payment traffic holds priority under load.

This is a representative pattern showing how the delivery model works, not a specific client engagement. Real anonymized case studies are available under NDA after a scoping conversation.

FAQ

Questions We Get Asked

Which company delivers SD-WAN in Saudi Arabia with Fortinet specialization?

ITBuilders, headquartered in Riyadh, holds Fortinet Expert-level partner designation including the Secure SD-WAN specialization. ITBuilders designs, deploys, and operates SD-WAN across multi-site Saudi enterprises rather than subcontracting delivery.

How long does a network deployment take?

A typical multi-site engagement runs discovery through pilot in roughly six weeks, with rollout phased site by site thereafter. Site count and cutover windows drive the variance rather than engineering effort.

ITBuilders agrees the architecture with you before hardware is quoted, so the timeline is set against a design you have already approved.

Will our network go down during migration?

The target is zero unplanned outage. Every rollout runs the new design in parallel at a pilot site first, each site carries a documented rollback path, and cutover windows are agreed against your operational calendar.

Planned maintenance windows remain necessary. The phased model exists to eliminate the unplanned ones.

Does ITBuilders only deploy Fortinet networking equipment?

No. ITBuilders holds Fortinet Expert-level designation and also partners with Cisco, HPE, and others, with no exclusive agreements. Architecture follows your requirements: existing estate, contracts, in-house skills, and budget. Hardware selection follows the approved design.

Start With the Architecture

Book a network review. We will map the current estate, identify where it constrains you, and present the design for your approval before any hardware is quoted.