The development of network technology demands reliable, efficient, and secure connectivity, especially for institutions with high operational needs. Software-Defined Wide Area Network (SD-WAN) emerges as an innovative solution to overcome the limitations of traditional networks, such as reliance on a single internet service provider (ISP) and inadequate security. This research aims to implement Maximize Bandwidth (SLA) on SD-WAN technology with firewall policies in Fortigate Next-Generation Firewall (NGFW) to improve network performance and security at Institution XYZ. The research method involves network simulation using Graphical Network Simulator 3 (GNS3) with a tree topology, two ISP clouds, and Fortigate configuration as NGFW. Testing was conducted through bandwidth monitoring, ICMP testing, and network parameter measurement using Iperf3. The results show that the implementation of SD-WAN with the Maximize Bandwidth (SLA) method successfully optimized bandwidth distribution and reduced connection disruptions. The implemented firewall policies were also effective in network segmentation, restricting inter-divisional access, and enhancing security. Testing confirmed network stability with a consistent bitrate of 1.05 Mbits/sec, low jitter (0.371–0.841 ms), and no packet loss. In conclusion, this solution not only addresses bandwidth limitations but also improves network security, thus serving as a reference for other institutions facing similar challenges.