VLAN vs Hardware Interface performance and security
I'm getting ready to replace an ASA with an FG200E. On the ASA I have a portchannel of all 6 GBE interfaces and all my firewall interfaces are vlans beneath that portchannel. Before I do the same thing on the FG I thought should see if there are any reasons not to do that. I know from experience that FG has some pretty goofy restrictions on how interfaces can be configured, like not being able to use aggregated and individual interfaces in the same vlan.
So here are my concerns in particular: I have 14(ish) vlans. I want to create each vlan interface under a 6 port aggregate (PortChannel1).
I will be enabling things like LDAP/AD authenticated browsing, virus, forticlient, etc.
Are the WAN1/2 interfaces “special” in some way that I should be concerned about?
Is there any performance hit on the FG in using a lacp aggregate of 6 physical interfaces rather than individual interfaces?
I may want to add a second 200E for HA. Anyone know if there are any problems/restrictions when using HA and Aggregated links? Other thoughts in general about using aggs in the FG?
