Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
capricorn80
New Contributor II

Fortigate 100E act as back bone core router and firewall

Hi!

 

We have two Fortigate 100E active/passive and three switches. As I dont have any core redundant switches so I want to implement redundancey in the FW. 

The SVI lives on Firewall and the ports are trunk between three switches and Firewall. As FW has 16 ports acting as internal switch. I want to use 12 of them for this topology.

 

Can any expert give basic idea about its implementation?

 

Thanks

6 REPLIES 6
capricorn80
New Contributor II

Adding image if someone can suggest. 

 

Thanks

 

 

capricorn80

anyone ?

RockIT
New Contributor III

Are you using fortiswitch with fortlink or any other brand?  I have this setup with 80E, 100E, and 600D.  

 

Fortilink: Hookup a port to each firewall.  Setup VLANS under switch managment and assign profiles to different vlans.  I also have pri internet vlan with no IP used to share the internet connection to the two firewalls.  I segment the servers from the workstations and use rules for internal routing and policy control.

 

Works well with about 80 users on the 100E so far.  Haven't had any issues.  Love using the fortiswitch which can tell you what devices are on what port of the switch and allow you to assign vlans to the port all through the firewall.

capricorn80
New Contributor II

I will use aggregation ports and then use VLAN in it. See the rough pic.

 

 

 

 

RockIT
New Contributor III

That should work well.

 

capricorn80
New Contributor II

yes thats the plan :)

Labels
Top Kudoed Authors