Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yas13899
New Contributor II

Internal network best design

Hello...

 

I have a FortiGate 600E device... 

In the current design there is one internal interface that connects all internal vlans to the firewall:

(10 users vlans, 1 guests WIFI vlan, 1 Servers Farm vlan)... This connection comes directly from a Cisco Nexus 9396 switch which is the default gateway for all of the vlans.

 

Now I want to separate these vlans from each others in order to set policies between the users' vlans, WIFI vlan and server farm vlan...  What I know is that I have to setup the vlans in the internal connection of FortiGate device and make it the default gateway for them instead of the Nexus switch.. Is this the right way??

And can the FortiGate 600E handle the routing instead of the Cisco Nexus device??

 

Any advice will be appreciated 

1 Solution
Toshi_Esumi
SuperUser
SuperUser

Yes and no, I guess. Moving the GWs for those VLANs from the Nexus switch to the 600E is only way to force inter-VLAN traffic to come to the FGT to regulate. The 600E probably can handle most of routing (L3) features you're currently doing with the Nexus but it might not do much of switching features unlike Nexus, ex. no access ports. So I would recommend leaving L2 features on the Nexus.

 

Toshi

View solution in original post

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

Yes and no, I guess. Moving the GWs for those VLANs from the Nexus switch to the 600E is only way to force inter-VLAN traffic to come to the FGT to regulate. The 600E probably can handle most of routing (L3) features you're currently doing with the Nexus but it might not do much of switching features unlike Nexus, ex. no access ports. So I would recommend leaving L2 features on the Nexus.

 

Toshi

yas13899
New Contributor II

Thank  you very much

In fact there is no need for any switching capabilities... Just isolating and controlling L3 and above traffic

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors