Best Practice: Connect Third-Party WAP to switch or FortiGate port2?
I have a FortiGate 60E in a small office. I am using a UniFi wireless AP for wifi. Everything is working fine, but I have a question about best practices.
Currently, the WAP is connected to the same switch that all computers are connected to, like this:
FG60E (port1-7) <> NetGear switch <> WAP & computers
Everything works well. Only the FG60E hands out DHCP IPs. The WAP and all computers are on the same subnet (192.168.33.x). Simple.
Would this setup be "better?"
FG60E (port1-6) <> NetGear switch <> Computers
FG60E (port7) <> WAP
I would create a new interface for port7. I'd assign this interface 192.168.34.1 and let DHCP hand out 192.168.34.50-100.
So my wireless devices would be on a separate network. I'd create policies to allow the wireless devices to access to the Internet (WAN1) and one printer on the 192.168.33.x network.
Thoughts?
