Hi all,
I'm going to configure a FG 60E for a school. We would like to take advantage of VDOMs (up to ten) because the firewall will serve also other tenants
I have to plan the network from scratch, firewall included and unfortunately I don't have physical access to it to play with the commands.
I would like the maximum flexibility in assigning a public IP address to VDOMs without using NAT and for this reasons I would forget of the WAN1/WAN2/DMZ interfaces and go for a trunk of four (or even six) interfaces and then create SVI (sorry I use Cisco ternimology) that I will assign to VDOM based on the needs.
As I said In this way each VDOM may have the possibility to be exposed to the Internet with NATted IP address. We have a /27 prefix assigned.
Does anyone have any objection/advice on this approach? Will we loose any feature by configuring the 60E in this way?
Non very important but is any feature for dual-homing tightened to the physical WAN1/WAN2 interfaces or such feature can be used on any interface?
Any feedback will be much appreciated :)
Alex
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Ken,
good point. Being the 60E in the lower part of the Fortinet portfolio I had the same doubt but it seems it can be done unless I'm missing something really obvious: https://docs.fortinet.com/document/fortigate/6.2.0/new-features/226063/lacp-support-on-entry-level-e...Thanks,
Alex
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.