Combine "VLAN per Port" with "VLAN per ID"
Hello
Normally when I configure a FortiGate (which isn't too often anyway) I create VLANs with VLAN IDs and then work from there (assign specific ports in the switch to the desired VLAN ID respectively assign specific SSIDs in the access points to the desired VLAN ID).
Now I "inherited" a network with a FortiGate that has been set up by a previous IT guy. They used a method that I didn't even knew that it existed. They assigned one port on the FortiGate to one VLAN and the other ports to another VLAN.
Now this lead to the problem that the "Guest WiFi" actually wasn't separated from the "Office WiFi" because the access points of course were connected to one port (or rather: a switch that is connected to a port on the FortiGate) - and since everything that comes through this port is determined to be in the same VLAN, everything that comes from the access point is in the same VLAN as well.
So my question is:
Can we somehow "combine" the two methods of VLAN management, so that we don't have to redo the complete VLAN setup?
There are still a few ports on the FortiGate unused, so maybe we could hook the access points to those and then configure it in a way that those ports don't predetermine a VLAN and instead use VLAN IDs (transmitted by the access points based on which SSID the client is on) are used?
Thank you!
