Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Infotech22
Contributor

Segmenting our Network

Hello to all Cybersecurity enthusiastic,

I would like to get some best practices, advices for my next project.

On one location we didn't do barely any segmentation since last IT Manager so it's time to make it more secure and better.

Current Situation is like this:

  • VLAN 1 "Clients"
    • Here in our Clients VLAN we have regular clients (notebooks, workstations), printers, VoIP devices, meeting devices (cameras, microphones etc)
  • VLAN 2 "Servers"
    • Here in Servers VLAN we have domain controllers, file servers, backup servers, repositories etc

What would be a general recommendation?
I would like to segment it a bit more and create separate VLANs for Printers, VoIP, IoT, Backup Network etc.

Our Infrastructure is as follows:
2 x FortiGate 200F in an HA Cluster (Active/Passive)
2 x Core FortiSwitches in an MC-LAG
3 X Access FortiSwitches

 

I'm new to this forum.
I'm NSE4 certified. 

1 Solution
ndumaj
Staff
Staff

Hello Infotech22,

You can add additional VLANs on the interfaces in order to segment your network.
Please review the following article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-a-VLAN-tagged-interface-802-...

- Then firewall policies should be created to allow traffic from the switch interface to the interface or the VLAN to reach. NAT should be enabled were it is needed.

-BR-

- Happy to help, hit like and accept the solution -

View solution in original post

12 REPLIES 12
Infotech22

Yes, that would be a smart approach

I have time to plan so baby steps for now :)

Infotech22
Contributor

One more question for all of you :)
If I have VLANs with different subnets,
Examples:

  • Clinets: 10.10.0.1 /23
  • Printers: 10.10.255.1/24

Our Forti Infrastructure is MCLAG, does this means that traffic for clients to printers will go first to FortiGate then back to FortiSwitchse since this is Routing between subnets?

ndumaj
Staff
Staff

Hello,
As far the SW are managed by FGT is the FGT that will manage the traffic and routing part.
If you run a sniffer or PCAP on FGT GUI you will see traffic how it is going on FGT.
-BR-

- Happy to help, hit like and accept the solution -
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors