Skip to main content
Chrispike89
New Member
September 5, 2019
Question

Seperate Computers and Cellphones on the same Network with Different IP addresses

  • September 5, 2019
  • 1 reply
  • 7963 views

Good Day

 

I am Fairly new to Advanced Fortigate settings.

 

This is my Idea and how my infrastructure is currently setup, After-which i will explain what i am trying to do.

 

I have a Fortigate 100E - 5 HPE Switches - 5 UniFi AP's 

 

WAN2 - Wireless Internet

WAN1/SPF1 - Fiber Internet (currently awaiting fiber installation)

 

Port 1 - Connected to Switch 1 & 2 - PoE switches connecting IP phones to PABX and internet for Times

Port 2 - Connected to Switch 3, 4 & 5 - HPE switches connecting computers and laptops to Network & Internet

Port 3 - Connected to Security Camera System - Gives all cameras internet access for external viewing

 

(Unifi Ap's Connected to Switch 5 giving laptops and Cellphones internet with same IP range as Computers)

All the Above is Hardware switches configured on the Fortigate 100E

 

What I am trying to do...

 

I would like to keep the UniFi's on the same network but want them to be separate addresses to the computers.

Computer-PC with 192.168.0.1

Android 9.1   with 10.0.0.1

 

After achieving this I can then make rules for cellphones to use low bandwidth and restrict sites (keep people off Facebook and YouTube)

 

I have thought of making another hardware switch just for the WiFi but there are some laptops and computers that need to connect to the wifi (Faulty RJ45 ports etc)

 

I know there is a device inventory and would like to make use of it so that only computers connect to 192.168.0.1 and android and iphones connect to 10.0.0.1 

 

 

Thank you in advanced

    1 reply

    OneOfUs
    New Member
    September 5, 2019

    If you had FortiAPs you could create separate SSIDs for Computers and Phones.  Computer SSID would let bridge the the local network (or tunnel for more policy control) and Phone SSID would tunnel to the Fortigate.

     

    In your case, you can see if you can create separate SSIDs and assign them to different VLANs.  You can then layer 2 the VLAN to the Fortigate for policy control.

    Chrispike89
    New Member
    September 6, 2019

    Thank you for your reply.

     

    The UniFi AP's where from the old building and we needed to cut costs, Im not familiar with Vlans on fortigate and Unifi's but I will do some digging to see what i can do in that regard.

    SecurityPlus
    Explorer III
    September 6, 2019
    We did an installation where we did what Chrispike98 suggested and it appears to work well. We are not using device invitory.