We are looking at FortiAPs and FortiSwitch(es) as alternatives to other hardware vendors we currently have deployed in our environment. Specific use case is residence hall wireless utilizing hospitality-style APs along with switch replacement.
I'm curious about your experience with deploying Fortinet's APs and switches in a large-ish environment.
In our case, around 900 APs and 50 switches.
Thank you in advance for any feedback on this.
I have been involved in large school districts with many switches and aps. Replacing it with the ecosystem makes is very easy to manage and inspect/segregate your traffic. Everything has been running very well and upgrades will take some time based on your topology but have never had any major issues, just always read your compatability guides first.
We have not used fortimanager because it all came back to one set of fortigates so didn't see much value.
One thing to consider is bridge vs tunnel for ap management.
We did a retirement home that had 2 aps in each room and ended up creating a network that bridged the SSID and ports in those two aps for each room. Not sure if you are making the wired ports hot or not.
Thank you for your comments. We will be enabling the wired ports on the APs. While not a lot of students use the ports, the ones that do usually plug in their TVs, gaming systems or computers.
We are used to CAPWAP tunnels back to controllers in our existing environment. But we haven't decided on which way we would go on that. Still in the exploration phase. Aside from supporting half as many APs on the FG, do you see any advantages/disadvantages with bridging over tunneling in a Fortinet deployment?
Bridging has less overhead on the FortiGate CAPWAP processes, etc, and allows local device communication on the switch ports, vs all the traffic going to the firewall. This means you can't inspect it all, but it will reduce load on the uplinks.
User | Count |
---|---|
2626 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.