Software switch vs VLAN - Fortigate 100e
Good morning!
I am looking for best practices/recommendations for utilizing the built in switch on a Fortigate 100e, in particular with configuring the switch to split the ports between internal LAN and DMZ. I do not need all 16 ports on the Fortigate and would like to split the switch up as follows:
Ports 1-4 = Internal LAN
Ports 5-8 = DMZ
Ports 9-12 = Potential for WAP connections
Ports 10-16 = Unused and unconfigured/disabled
I am new to Fortigates, coming into a new network from a WatchGuard/Cisco background and would like to see what others have done to optimize the usage of the switch ports. I can see advantages to configuring software switches as described above, but would like to explore configuring VLANs on individual ports if it would be more applicable.
There are currently separate VLANs for servers, workstations, phones, and guest wifi access. I can see dropping a number of VLANs and using QoS for my phones, but my hands are tied on the separate VLAN for the guest wifi as there is a need for both internal and external wifi, but only a single network port on the available WAPs.
Any recommendations would be greatly appreciated!
