Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
axlmac
New Contributor

FG 60E with all the interfaces on a trunk, would you recommend this approach for a school?

Hi all,

 

I'm going to configure a FG 60E for a school. We would like to take advantage of VDOMs (up to ten) because the firewall will serve also other tenants 

 

I have to plan the network from scratch, firewall included and unfortunately I don't have physical access to it to play with the commands.

 

I would like the maximum flexibility in assigning a public IP address to VDOMs without using NAT and for this reasons I would forget of the WAN1/WAN2/DMZ interfaces and go for a trunk of four (or even six) interfaces and then create SVI (sorry I use Cisco ternimology) that I will assign to VDOM based on the needs.

As I said In this way each VDOM may have the possibility to be exposed to the Internet with NATted IP address. We have a /27 prefix assigned.

 

Does anyone have any objection/advice on this approach? Will we loose any feature by configuring the 60E in this way?

 

Non very important but is any feature for dual-homing tightened to the physical WAN1/WAN2 interfaces or such feature can be used on any interface?

 

 

Any feedback will be much appreciated :)

 

Alex

10 REPLIES 10
axlmac
New Contributor

Hi Ken,

 

good point. Being the 60E in the lower part of the Fortinet portfolio I had the same doubt but it seems it can be done unless I'm missing something really obvious: https://docs.fortinet.com/document/fortigate/6.2.0/new-features/226063/lacp-support-on-entry-level-e...Thanks,

 

Alex

Labels
Top Kudoed Authors