Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fdigio
New Contributor

Best network topology for DMZ

Hi everyone

I am setting a DMZ for a internet facing server (basically a synology NAS accessible via HTTPS). 

I want to secure it with a DMZ that is accessible also for our internal user. What's the best settings for my need?

 

Those are the 2 solutions i imagined, but feel free to correct me if i am wrong:

 

Solution 1:

 

Screenshot 2023-05-09 at 18.06.53.png

Solution 2:

 

Screenshot 2023-05-09 at 18.06.45.png

 

Thanks!

2 REPLIES 2
gfleming
Staff
Staff

Both options work. If you want pure separation (logical and physical) then Solution 1 is best.

Cheers,
Graham
Toshi_Esumi
SuperUser
SuperUser

Graham beat me while typing my comment. I would also say not much different between them as long as the switch is handling only L2 switching. The secirity you need is acomplished by the firewall policy at L3 or above.

 

Toshi

Labels
Top Kudoed Authors