Hello NAC admins,
I would like to know which network type is recommended in FortiNAC configuration, Layer 2 or Layer 3 ? What's really difference between the two ?
Thanks in advance
BR,
Solved! Go to Solution.
A Layer 2 network type can be considered when FNAC is deployed as a hardware appliance at the edge perimeter and directly connected to the switch infrastructure. This setup also supports trunking, which can simplify configuration. When FNAC is deployed as a virtual machine or as physical appliance in the data center, using a Layer 3 network becomes necessary, as the isolation VLANs should not be extended to the data center. Nevertheless, FNAC offers flexibility, and the deployment type should be chosen based on the specific network requirements.
hi,
Thank you for your answer.
From that article, the Layer 3 configuration appears to be the most suitable option. I do have another question that might seem basic, my apologies in advance.
In the “Basic Network” section, specifically under the “Domain” field in the DNS configuration, does this need to be a specific domain? Additionally, can the same domain be used for the isolation VLAN? I’m a bit unclear on that part
BR,
No it can't be the same domain.
Domain: Identifies the domain for this range of IP addresses. To help identify the VLAN, incorporate part of the name in the domain.
Note:
Example:
Hope it helps.
Hi AEK,
Thank you for your help, and that article did help, now it's much clear.
BR,
A Layer 2 network type can be considered when FNAC is deployed as a hardware appliance at the edge perimeter and directly connected to the switch infrastructure. This setup also supports trunking, which can simplify configuration. When FNAC is deployed as a virtual machine or as physical appliance in the data center, using a Layer 3 network becomes necessary, as the isolation VLANs should not be extended to the data center. Nevertheless, FNAC offers flexibility, and the deployment type should be chosen based on the specific network requirements.
Hello Emirjon,
Thank you so much for this detailed explanation, it is very clear now.
BR,
| User | Count |
|---|---|
| 2921 | |
| 1452 | |
| 858 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.