Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nonpe
New Contributor

SSTP VPN support and Layer 2 traffic control on FortiGate / FortiSwitch

Hello,

In one of the company’s offices, we are planning to completely replace the hardware equipment, which includes the following:
1. FortiGate-120G Hardware
2. FortiSwitch-1048E
4. FortiSwitch-148F-FPOE
5. FortiAP-234F

What concerns me is that, for some of the offices, the only available option for a SSTP VPN tunnel is, due to the fact that the providers block our other VPN solutions.

From forums, documentation, and various sources, it is stated everywhere that SSTP cannot be used.

Is it true that it is not possible to use SSTP at all?
The other question is whether it is possible to control Layer 2 traffic between computers.
By this I mean: if one computer attempts to attack another computer, and both are connected to the same switch, is there an integrated tool on the switch that would allow me to detect and block such an attack?

Thank you in advance for your time.

1 Solution
earingfabulous
New Contributor

FortiGate doesn’t natively support SSTP, so you’d need a Windows Server or another SSTP-capable device if that’s required.

For Layer 2, FortiSwitch supports VLANs, ACLs, 802.1X, and ARP/IP-MAC binding to isolate devices, but there’s no automatic attack detection at Layer 2 — segmentation and monitoring are key.
https://docs.fortinet.com/document/fortiswitch/7.4.4/fortilink-guide/756049/fortiswitch-security-pol... steal a brainrot

View solution in original post

2 REPLIES 2
earingfabulous
New Contributor

FortiGate doesn’t natively support SSTP, so you’d need a Windows Server or another SSTP-capable device if that’s required.

For Layer 2, FortiSwitch supports VLANs, ACLs, 802.1X, and ARP/IP-MAC binding to isolate devices, but there’s no automatic attack detection at Layer 2 — segmentation and monitoring are key.
https://docs.fortinet.com/document/fortiswitch/7.4.4/fortilink-guide/756049/fortiswitch-security-pol... steal a brainrot

nonpe

Thank you for your prompt and accurate reply

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors