Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ByteHaven
Contributor

FortiNAC network type

Hello NAC admins,

I would like to know which network type is recommended in FortiNAC configuration, Layer 2 or Layer 3 ? What's really difference between the two ?

Thanks in advance

BR,

1 Solution
ebilcari
Staff
Staff

A Layer 2 network type can be considered when FNAC is deployed as a hardware appliance at the edge perimeter and directly connected to the switch infrastructure. This setup also supports trunking, which can simplify configuration. When FNAC is deployed as a virtual machine or as physical appliance in the data center, using a Layer 3 network becomes necessary, as the isolation VLANs should not be extended to the data center. Nevertheless, FNAC offers flexibility, and the deployment type should be chosen based on the specific network requirements.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

6 REPLIES 6
funkylicious
SuperUser
SuperUser

"jack of all trades, master of none"
ByteHaven

Thank you for your answer.

 

From that article, the Layer 3 configuration appears to be the most suitable option. I do have another question that might seem basic, my apologies in advance.

In the “Basic Network” section, specifically under the “Domain” field in the DNS configuration, does this need to be a specific domain? Additionally, can the same domain be used for the isolation VLAN? I’m a bit unclear on that part

 

Config_Wizard_Network_type.pngVLANper_state.png

BR,

AEK
SuperUser
SuperUser

No it can't be the same domain.

 

Domain: Identifies the domain for this range of IP addresses. To help identify the VLAN, incorporate part of the name in the domain.
Note:

  • Avoid using a domain already existing in the production network. Otherwise, DNS resolution may not work properly for any names using that production domain that are part of the Allowed Domains List.
  • If you use agents for OS X, iOS, and some Linux systems, using a .local suffix in Domain fields may cause communications issues.

Example:

  • Production domain is megatech.com
  • For Isolation VLAN use megatech-iso.com
  • For Registration VLAN use megatech-reg.com

 

Ref: https://docs.fortinet.com/document/fortinac-f/7.6.0/configuration-wizard/143459/configure-lease-pool...

 

Hope it helps.

 
AEK
AEK
ByteHaven

Hi AEK,

Thank you for your help, and that article did help, now it's much clear.

BR,

ebilcari
Staff
Staff

A Layer 2 network type can be considered when FNAC is deployed as a hardware appliance at the edge perimeter and directly connected to the switch infrastructure. This setup also supports trunking, which can simplify configuration. When FNAC is deployed as a virtual machine or as physical appliance in the data center, using a Layer 3 network becomes necessary, as the isolation VLANs should not be extended to the data center. Nevertheless, FNAC offers flexibility, and the deployment type should be chosen based on the specific network requirements.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ByteHaven

Hello Emirjon,

Thank you so much for this detailed explanation, it is very clear now.

BR,

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors