Skip to main content
axlmac
New Member
May 30, 2020
Question

FG 60E with all the interfaces on a trunk, would you recommend this approach for a school?

  • May 30, 2020
  • 10 replies
  • 8889 views

Hi all,

 

I'm going to configure a FG 60E for a school. We would like to take advantage of VDOMs (up to ten) because the firewall will serve also other tenants 

 

I have to plan the network from scratch, firewall included and unfortunately I don't have physical access to it to play with the commands.

 

I would like the maximum flexibility in assigning a public IP address to VDOMs without using NAT and for this reasons I would forget of the WAN1/WAN2/DMZ interfaces and go for a trunk of four (or even six) interfaces and then create SVI (sorry I use Cisco ternimology) that I will assign to VDOM based on the needs.

As I said In this way each VDOM may have the possibility to be exposed to the Internet with NATted IP address. We have a /27 prefix assigned.

 

Does anyone have any objection/advice on this approach? Will we loose any feature by configuring the 60E in this way?

 

Non very important but is any feature for dual-homing tightened to the physical WAN1/WAN2 interfaces or such feature can be used on any interface?

 

 

Any feedback will be much appreciated :)

 

Alex

    10 replies

    lobstercreed
    New Member
    May 30, 2020

    There isn't any technical reason you can't do this that I am aware of, but I would be worried that you're putting too much load on a box this small based on how you've described it.  Others may have more experience with something like this though.

    axlmac
    axlmacAuthor
    New Member
    May 30, 2020

    Thanks Daniel,

     

    the number of users may be up to 200 though the concurrent ones might be around 50. As the majority is made of students indeed the FG would be called to do a lot of checks. The pipe to the Internet is 1Gibt/s and we will have to carefully choose up to which level of protection to push/enable on the FG.

     

    The implementation of having more than few VDOM might be postponed and done at will when maybe students have to learn firewalling.

     

    Many thanks for your precious reply,

     

    Alex

    emnoc
    New Member
    May 31, 2020

    This is called a firewall on a stick approach and I have done this many times when ports where limited. Unless you have limitation in your switch port type or availability, I see no reason to do a "firewall on a stick".

     

    Also if your interface is 1gbps your not going to get 1gbps with a "firewall on a stick".

     

    Where I used "firewall on a stick" where when 10/40gbe switchports where limited in the switch-fabric and or the model has a limited number ( i.e FGT5100D )

     

    Ken Felix

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!