Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CanterburyComputers
New Contributor

Best practice - How do I setup for 1 WAN connection and two subnets?

I have a customer with a single WAN connection and two separate subnets 192.168.10.x - used for internal office - also needs wifi configured 192.168.20.x - used for general public  Both subnets need internet access Ideally I would want to setup a separate port on the Fortigate for each subnet.

What is the best practice method of installing the Fortigate. Very much a novice! Thanks for your assistance.

5 REPLIES 5
emnoc
Esteemed Contributor III

You could do 2 multi-vdom and inter link  or just a single vdom. What is driving you to  key LAB subnet in two  ports for the uplink? Compliance, isolation, policy.....

 

I don't think a  BCP exist in this case, and your business objects might mandate what you do or not do, imho

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
CanterburyComputers

isolation of the business systems from the general publics network

 

emnoc
Esteemed Contributor III

So what does that mean? Does 192.168.10.x never  need  internet access { general public }? If that's the case, than place no firewall policies to allow for that.

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
CanterburyComputers

both subnets need internet access

sw2090

The most simple way is just set up one port for each subnet (alas you don't want to use vlans) and create an internet policy for each one. 

This also enables you to set trafficshapers or Web/URL Filters seperately for each.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors