Question
Fortigate with multiple dhcp pools on one interface
Hi, I have the following escenario: a fortigate 200E which handles internet access for all the internal network, 3 distribution L3 switches and several access switches. There are several vlans (around 20) and we want the fortigate to handle dhcp and internet access only, leaving the intervlan routing to the L3 switches. The fortigate has a connection to two of the L3 switches, and I know one interface can be configured as a dhcp server with mutiple ip pools through the cli, instead of creating a svi for each vlan and configuring dhcp for each (which we don't want to*). The links between the fortigate and the switches would be in a separate "internet access" vlan. What I want to know is this: with this scenario, is it still possible to configure policies separately for each vlan, despite all of them ultimately reaching the fortigate routed through the "internet access" vlan? * From what I understand, if I configure the svi's on the Fortigate but let the L3 switches be the gateway for all vlans, a situation of asymmetric traffic will happen, meaning the outgoing traffic will go through the internet acces vlan but the incoming traffic will go through each corresponding vlan, since the fortigate has an interface on every one of them; and this would cause a lot of trouble