I assume no traffic is needed/allowed from the guest wifi to other internal subnets on different ports, and vice versa.
The easiest, and thus the best, way to do it is separating vdom and put only wan2 and port8 in the new vdom. Otherwise you need to deal with policy routes, which get in your way every time you need to change something. Because you're going to have two default routes and route everything based on source subnets/IPs.
hmmpf...@Toshi is trading one complication for another...
Of course it all depends, on how much experience you have with firewalls, routing and Fortigates. Setting up a policy route is not more complicated than setting up a regular route. The only difference is that you have the PR match source addresses, a regular route only matches destination addresses.
My advice: set it up, document it briefly, and you're done.
VDOMs have advantages but are a pita in general - a VDOM is a complete virtual firewall within the same hardware. Every (!) time you change something in the config, you will have to specify which VDOM is concerned. Or it might be an item which is only configurable in the 'global' realm.
IMHO way too much hassle for this particular problem. But, YMMV.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.