We utilize Fortigate vdoms for many school districts. Currently, as recommended by Fortigate, we extend the school vlans across our WAN. The vlans become virtual interfaces on the Fortigate vdom which firewall policies are applied to. This works very well for us but, recently, this design caused issues on our WAN because of LAN issues at one of the districts bleeding over to the WAN. The solution we are currently implementing is to create a single, transient vlan and route all other vlan subnets through it to the Fortigate. This works for simple configurations but is not a viable solution for complex Fortigate configurations. The best solution would allow us to extend the district layer 2 vlans across a layer 3 connection and then pick up the vlan again at the Fortigate so it can be used as a virtual interface with the same subnet as what is used at the school district. (See drawing) .
The switches we are currently using are Aruba 3810s
”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.
-Mike Kapnisakis, Warner Bros
With your subscription - you'll gain access to our exclusive IT community of thousands of IT pros. You'll also be able to connect with highly specified Experts to get personalized solutions to your troubleshooting & research questions. It’s like crowd-sourced consulting.
We can't always guarantee that the perfect solution to your specific problem will be waiting for you. If you ask your own question - our Certified Experts will team up with you to help you get the answers you need.
Our certified Experts are CTOs, CISOs, and Technical Architects who answer questions, write articles, and produce videos on Experts Exchange. 99% of them have full time tech jobs - they volunteer their time to help other people in the technology industry learn and succeed.
We can't guarantee quick solutions - Experts Exchange isn't a help desk. We're a community of IT professionals committed to sharing knowledge. Our experts volunteer their time to help other people in the technology industry learn and succeed.