Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
richr
New Contributor

P2P L2 VLAN from FGT to Dorm Connections

Currently, we have a FGT 800C and hope to get the 1000C shortly. Right now, most of our Dorm areas are on a L3 network at each building, however creating ACLs each time is a pain and everytime having to update them is a pain as well (even with a script). Would it be recommended to use the 800C - create vlans/subinterfaces off one of the 10G ports and then trunk the VLAN to the dorm connections?
3 REPLIES 3
Jeff_FTNT
Staff
Staff

Yes, is doable to create vlans/subinterfaces off one of the 10G ports and then trunk the VLAN to the dorm connections. The ACL(policy) is more clear . 1. Old L3 policy Incoming Interface->Outgoing Interface, need use different " Source Address" to identify host 2. New L2 policy, it arrange with VLAN VLANxx1 ->Outgoing Interface VLANxx2 ->Outgoing Interface ... VLANxxx ->Outgoing Interface 3. Another options: you may try set up VDOM on FGT, each Dorm areas belong to one VDOM, it is easy to manage .
ede_pfau
SuperUser
SuperUser

I don' t really see your problem - could you elaborate a bit on ' every time...' ? Jeff' s suggestions are perfectly viable but IMHO do not offer more efficiency. Either you work with address groups (moving new members into a group), or you create a new VLAN and policy (which is work as well, even scripted). You could use ' interface groups' a.k.a. Zones to keep the number of policies low, and add a new VLAN interface just to the Zone when you create a new one. I would refrain from using one VDOM per dorm - the amount of overhead is not worth the effort. For 5+ VDOMs you would better use a FortiManager to manage them. In a way, the FM is scripting for VDOMs. So, what do you have to do ' every time' ? Add a user, add a subnet or VLAN?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
richr
New Contributor

Thanks. Every time in the sense of if a student brings a university owned device into the dorm, they would radius auth but then also need to pass health checks. However, if we implement a third party device to help with this, then each L3 device needs the ACL updated for this. I would create a " Guest Network" zone and put all the vlans in there. I thought I would want to use more features of the Fortinet, and let that do all of the processing...
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors