Bank branch network design / Solution design

Branch connectivity with a controlled recovery path

Combine diverse WAN services, restricted branch networks and an explicit surveillance policy for a financial-services location.

Finance environment for this solution design
Built around the way you workArchitecture · Equipment · Delivery
01

Separate transaction and surveillance traffic

02

Test both transport and tunnel failure

03

Keep recovery access controlled

Architecture / 01

How the solution connects

Independent uplinks meet a controlled network boundary. Local access is separated by purpose.

Branch connectivity with a controlled recovery path: proposed architecturePrimary branch circuit connects to Balance 580X (Primary path). RUTC50 cellular WAN connects to Balance 580X (Alternate WAN). Balance 580X connects to Security + access layer (Policy boundary). Security + access layer connects to Branch applications (Separate zone). Security + access layer connects to CCTV isolated network (Separate zone). Security + access layer connects to Staff wireless (Separate zone). Logical overview; final cabling and firewall rules are specified during design.01 / TRANSPORT02 / CONTROL03 / DISTRIBUTE04 / ACCESS ZONESWANBACKUPPrimary branch circuitRUTC50 cellular WANBalance 580XSecurity + access layerBranch applicationsCCTV isolated networkStaff wireless
Logical data pathBackup / optional transportConceptual design · final ports, policies and quantities are specified for the site
Read the connection map
  • Primary branch circuitBalance 580X · Primary path
  • RUTC50 cellular WANBalance 580X · Alternate WAN
  • Balance 580XSecurity + access layer · Policy boundary
  • Security + access layerBranch applications · Separate zone
  • Security + access layerCCTV isolated network · Separate zone
  • Security + access layerStaff wireless · Separate zone

The challenge on the ground

Two ISP contracts can still share a duct, upstream carrier or building power supply. A branch design must identify these shared dependencies and distinguish a failed internet path from a failed tunnel endpoint.

Surveillance uploads and software distribution should not consume the capacity reserved for branch applications during recovery.

Inside the design

Use a Peplink Balance 580X to manage the branch WAN transports and terminate a SpeedFusion tunnel at a properly hosted FusionHub endpoint. Connect a RUTC50 cellular router as an additional Ethernet WAN when required.

Place the institution’s approved security controls at the branch/service boundary; a multi-WAN router is not a substitute for the bank’s security architecture. Keep staff, surveillance, visitors and management isolated through managed switching and explicit policy.

Operating it day to day

Define which applications require tunnel continuity and which may use ordinary internet egress. Size the cloud endpoint and its network capacity for the aggregate branch load, and document its own recovery path.

Agree camera retention, operator access and export procedures separately. Keep administrative access attributable and test the branch while monitoring records actual path changes.

What to test before handover

  1. Fail each WAN transport independently during an approved test workflow.
  2. Interrupt the tunnel endpoint and verify the documented recovery action.
  3. Confirm CCTV and visitor isolation from branch applications.
  4. Check backup capacity with surveillance uploads limited.

Technical references

Equipment / 02

The bill of materials

5 scoped items

One branch with staff terminals, meeting rooms and an existing camera system. Availability targets determine whether paired edge devices are needed. Quantities below describe the example; your proposal confirms the final equipment and services.

01In this design
Peplink

Peplink Balance 580X

BPL-580X

Multi-WAN branch router

View product
02In this design
Peplink

Peplink FusionHub 100

FHB-100-A

Virtual tunnel endpoint

Requires a supported host, public connectivity and an appropriate licence tier.

View product
03In this design
Teltonika

Teltonika RUTC50 5G router

RUTC50210000

Diverse cellular transport

View product
04In this design
Cisco

Cisco Catalyst C1300-8P-E-2G switch

C1300-8P-E-2G

Branch access switch

View product
05In this design
Cisco

Cisco CW9172I indoor access point

CW9172I-CFG

Indoor staff wireless

View product

Complete the installation

The equipment above is one part of the project. Include these items in the final scope.

  • Institution-approved firewall/security services
  • FusionHub hosting and Peplink entitlements
  • Carrier services and UPS
  • Camera system and retention storage
Details worth knowing

Questions before you specify

Are two circuits sufficient for branch resilience?

Only if the complete service path is designed for the required recovery. Check carrier routing, power, edge hardware, tunnel endpoints and application dependencies.

From reference to reality / 03

Let’s design it for your site.

Send us the details below. We can turn the reference architecture into a scoped design, equipment schedule and quotation.

Start your project

Bring these to the first conversation

  • 01Application/tunnel requirements
  • 02Carrier route diversity
  • 03Institution security standards
  • 04Camera retention and recovery objectives
← Explore all solution designs