I deal with the network & IT at a small business and will be looking to get a standalone firewall as our current one is just a basic one that comes with the routers.
My question is can you have 2 separate networks using the same firewall? I dont want to join them in anyway as they must be kept separate for security reasons.
My thoughts where to setup as below (providing the firewall can go in front of the routers?)
Router 1 > Switch > Computers
Internet > Firewall >
Router 2 > Switch > Computers
hi,
and welcome to the forums.
There are different degrees of "security" and "isolation" of 2 networks. One would be to run 2 VLANs which cannot communicate with each other without the help of a router.
In your sketch, you don't need routers on each network as the FGT will / can do the routing.
You haven't mentioned if both networks share the infrastructure, i.e. run over the same cabling. If yes, VLANs are a practical way to keep them apart.
For higher requirements, you can virtualize the FGT. Actually, you can create 10 (9+1) virtual FGTs without any costs. This would isolate even the routing and firewall management for both networks, completely with admins, default routes, ISPs, policies etc. Of course, administration is a bit more evolved then.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.