Hi Jonathan1993,
There are a few options in regards to authentication on the network however, since you already have Azure AD and doesn't sound like you have any on-prem radius servers or FortiAuthenticator I would be looking at authentication with Azure AD as a SAML IdP.
Outbound firewall authentication with Azure AD as a SAML IdP | FortiGate / FortiOS 7.4.0 | Fortinet ...
As for the interfaces and splitting employee and guest networks, I would have separate firewall interfaces with VLAN's on switch. If you had spare interfaces, I would create aggregate interfaces for increased bandwidth.
Alternatively, if you had other plans and didn't want to use that many interfaces you could also create a sub-interface on the Fortigate and setup a trunk on the switch however, the first option would be my preferred.
Hope that makes sense.
Regards,
Dan.
Hi Jonathan1993,
I just seen the date on your original post, I'm assuming you're up and running now. Would be nice to hear what design you went with in the end! :D
Regards,
Dan.
User | Count |
---|---|
2140 | |
1189 | |
770 | |
451 | |
347 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.