Segmenting our Network
Hello to all Cybersecurity enthusiastic,
I would like to get some best practices, advices for my next project.
On one location we didn't do barely any segmentation since last IT Manager so it's time to make it more secure and better.
Current Situation is like this:
- VLAN 1 "Clients"
- Here in our Clients VLAN we have regular clients (notebooks, workstations), printers, VoIP devices, meeting devices (cameras, microphones etc)
- VLAN 2 "Servers"
- Here in Servers VLAN we have domain controllers, file servers, backup servers, repositories etc
What would be a general recommendation?
I would like to segment it a bit more and create separate VLANs for Printers, VoIP, IoT, Backup Network etc.
Our Infrastructure is as follows:
2 x FortiGate 200F in an HA Cluster (Active/Passive)
2 x Core FortiSwitches in an MC-LAG
3 X Access FortiSwitches
I'm new to this forum.
I'm NSE4 certified.
