FortiPAM Topology- Device Placement
This may be too broad of a question, but will ask in the event some replies or questions may provide any guidance at all. We just ordered FortiPAM, but am struggling on placement of the device based on the design documentation as per this link https://docs.fortinet.com/document/fortipam/1.6.0/administration-guide/541708/fortipam-designs. Most VLANS at HQ (1st floor, second floor, 3rd floor, servers...) reside on an Layer 3 Aruba 5406Z switch and the respective VLANS are trunked down to access switches. Our FortiManager and FortiAnalyzer also belong to the server VLAN on the 5406Z. We have one switch port directly connected to the firewall with appropriate routes in and out. We also have SSL-VPN on this firewall and connectivity to remote sites are via SDWAN ADVPN. Additionally, we have FortiClient EMS cloud. Any suggestions on placement of FortiPAM? Does it need to be on it's own interface on the firewall? There is mention in the article about single or multiple interface design but all examples I find are where the critical devices are segmented.
