Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kwhelchel
New Contributor

System Layout

Hello,

Looking to see if this is possible to do with in the fortigate 30E and 50E, for port access and utm.

Port 1 on firewall links to all pc's on the network that is protected by utm etc.

port 2 is linked to secured wifi units, these need to be able to pass data to the port one but needs to be protected by the utm functions and and be on separate vlan. to allow secure and protected communications between the ports and separate vlans

 

Thanks

Keith

2 REPLIES 2
tanr
Valued Contributor II

I'm not familiar with the 30E or 50E directly, but I think the 100D and 300D I work with aren't that different.

 

If you want to use vlans for the separation you would probably need a vlan capable switch (or two) that your ports 1 and 2 would connect to, since FortiGates only do tagged vlans.  The switch or switches would then have untagged vlan ports that your PCs and wifi access points would connect to.  If your access points are FortiAPs then you would need to allow CAPWAP on port 2, and you could set up the FortiAPs to tunnel back to the FGT if needed.

 

A couple thoughts, though.

 

If you have a switch for each port and are using different subnets you don't have to use vlans for the separation, and thus don't need to use vlan aware switches.  The FGT security policies can give you the separation.  If you are using a single switch (or might in the future) then vlans give you the L2 separation you need.

 

If you have wifi and PCs on different subnets (and possible vlans) you'll lose a lot of the ease of use.  Since they're in different broadcast zones a device on your wifi subnet/vlan won't automatically see a printer on your PCs' subnet/vlan, etc. etc.

 

If you've got a more detailed description of your situation that would help get better suggestions.

kwhelchel
New Contributor

each port will be connected to a separate switch. The application is for point of sale systems that needs separation on the network  for compliance, instead of using multiple firewalls between the networks.

Thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors