Question
need network advice
Hello everyone,
I have a newly deployed FortiGate firewall with an active license.
I would like to separate the internet path used by the FortiGate itself (FortiGuard updates, DNS, NTP, firmware checks, etc.) from the internet path used by LAN users accessing the internet.
My setup includes a router between the FortiGate and the internet.
What is the best practice to make:
- FortiGate local-out/update traffic go through one WAN/interface/path
- User LAN-to-WAN internet traffic go through another WAN/interface/path
Should this be done using:
- Local Out Routing
- Policy Based Routing
- SD-WAN
- or Static Routes?
Any recommended architecture or examples would be appreciated.
Thank you.
