Skip to main content
ByteHaven
Explorer III
November 2, 2025
Solved

FortiNAC network type

  • November 2, 2025
  • 6 replies
  • 713 views

Hello NAC admins,

I would like to know which network type is recommended in FortiNAC configuration, Layer 2 or Layer 3 ? What's really difference between the two ?

Thanks in advance

BR,

Best answer by ebilcari

A Layer 2 network type can be considered when FNAC is deployed as a hardware appliance at the edge perimeter and directly connected to the switch infrastructure. This setup also supports trunking, which can simplify configuration. When FNAC is deployed as a virtual machine or as physical appliance in the data center, using a Layer 3 network becomes necessary, as the isolation VLANs should not be extended to the data center. Nevertheless, FNAC offers flexibility, and the deployment type should be chosen based on the specific network requirements.

6 replies

funkylicious
SuperUser
SuperUser
November 2, 2025
ByteHaven
ByteHavenAuthor
Explorer III
November 2, 2025

Thank you for your answer.

 

From that article, the Layer 3 configuration appears to be the most suitable option. I do have another question that might seem basic, my apologies in advance.

In the “Basic Network” section, specifically under the “Domain” field in the DNS configuration, does this need to be a specific domain? Additionally, can the same domain be used for the isolation VLAN? I’m a bit unclear on that part

 

Config_Wizard_Network_type.pngVLANper_state.png

BR,

AEK
SuperUser
SuperUser
November 2, 2025

No it can't be the same domain.

 

Domain: Identifies the domain for this range of IP addresses. To help identify the VLAN, incorporate part of the name in the domain.
Note:

  • Avoid using a domain already existing in the production network. Otherwise, DNS resolution may not work properly for any names using that production domain that are part of the Allowed Domains List.
  • If you use agents for OS X, iOS, and some Linux systems, using a .local suffix in Domain fields may cause communications issues.

Example:

  • Production domain is megatech.com
  • For Isolation VLAN use megatech-iso.com
  • For Registration VLAN use megatech-reg.com

 

Ref: https://docs.fortinet.com/document/fortinac-f/7.6.0/configuration-wizard/143459/configure-lease-pool-domain

 

Hope it helps.

 
AEK
ByteHaven
ByteHavenAuthor
Explorer III
November 2, 2025

Hi AEK,

Thank you for your help, and that article did help, now it's much clear.

BR,

ebilcari
Staff
ebilcariAnswer
Staff
November 3, 2025

A Layer 2 network type can be considered when FNAC is deployed as a hardware appliance at the edge perimeter and directly connected to the switch infrastructure. This setup also supports trunking, which can simplify configuration. When FNAC is deployed as a virtual machine or as physical appliance in the data center, using a Layer 3 network becomes necessary, as the isolation VLANs should not be extended to the data center. Nevertheless, FNAC offers flexibility, and the deployment type should be chosen based on the specific network requirements.

Emirjon
ByteHaven
ByteHavenAuthor
Explorer III
November 3, 2025

Hello Emirjon,

Thank you so much for this detailed explanation, it is very clear now.

BR,

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.