Skip to main content
kssupport
Visitor III
March 27, 2026
Question

configure FG-71G - need advice for newbie

  • March 27, 2026
  • 1 reply
  • 226 views

hi there,

need advice, and some helps for best setup to my needs.

I just bought Fortigate FG-71G.

this fortigate will manage:
- 4 ISP: ISP_1, ISP_2, ISP_3, ISP_4. only ISP_1 and ISP_2 have public IP.

- this fortigate will connect to another fortigate use VPN IPSEC via ISP_1 (backup with ISP_2) if ISP_1 down.
- also will use VPN SSL use connection ISP_1, backup with ISP_2 if ISP_1 down.

 

- 5 unit floor (each floor can't communicate each others, unless require different, (unit_A to Unit_E) with:
1. unit_A
- don't have access internet
- can communicate with unit_B, with limited services.

2. unit_B
- will have access internet via ISP_4.
- can communicate with unit_A, with limited services.
- if some case ISP_4 down, it may use ISP_3 (configure/ switch manually)

3. unit_C
- will have access internet via ISP_4
- need divide into 3 groups, but can access 1 shared printer.
- each groups can't communicate each other (except to shared printer). shared printer will be connect to Active directory in same network.
- if some case ISP_4 down, it may use ISP_3 (configure/ switch manually)

4. unit_D
- will have access internet via ISP_3
- if some case ISP_4 down, it may use ISP_3 (configure/ switch manually)

5. unit_E
- will have access internet via ISP_1 or ISP_2 (can be auto balance, or fail over).
- need divide into 2 groups.
- if possible, specifically group_1 use ISP_1 , group_2 use ISP_2 (optional).
- each groups can't communicate each other
- all groups can access shared printer on unit_C

is that possible to implement above conditions?

 

currently I only use unmanaged Switch hub. if there will be need managed switch, please advice layer 2 or need layer 3, and at what point I need to attach.

thank you

1 reply

Jean-Philippe_P
Staff & Editor
Staff & Editor
March 29, 2026

Hello kssupport, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Jean-Philippe - Fortinet Community Team
kssupport
kssupportAuthor
Visitor III
March 30, 2026

thanks Jean for feedback. yup, still preparing for setting, and find as many as advice.by the way, currently we use FG60F. seems we avoid to use auto converter, because we will use SDWAN feature for this time. I search SDWAN already stable.

but i still learn it is capable / reliable for IPsec.

plan is only ISP_1 and ISP_2 as member SD WAN.

looking update from this forum.

thank you.

Toshi_Esumi
SuperUser
SuperUser
March 30, 2026

If you don't want to put the IPsec in one of SD-WAN members, it's should be quite simple after putting each "unit" or "group" on different VLANs (sub-interface). Then just set up policies to control access or no access.
You already know what to do if you currently use a 60F.
By the way, I don't think SSLVPN is available on any G-series. You have to use dialup IPsec VPN.

Toshi