BO and VLANs
Hello,
We have a couple of BO where security is very bad so we want to have separate VLAN just for each of these BOs.
Our goal is to have one VLAN for each BO with one subnet on it for workstations. That VLAN needs only internet access. Now, besides this simple configuration, we would like to have access to each of these PCs from HQ workgroup VLAN for remote support.
In this case, do we need to:
- create VLAN on HQ and BO FGs?
- Make DHCP on VLAN at HQ or BO?
- If we have to create (and I think we have to) VLAN on HQ FG, do we create that VLAN on the same physical interface where we have other VLANs for HQ?
- Firewall policy on HQ or BO FGs?
Thank you in advance!
