Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lhsit
New Contributor III

Transparent Mode vs Virtual Wire Pair

Hello All,

 

I'm newly returned to the Fortigate products after using them briefly at a previous job a few years ago.  We are a high school and have just purchased a 600D mostly for content filtering and firewalling off our internal network.

 

Unfortunately, our education department (ie 'district') controls our router and we cannot make any changes so we have to place our Fortigate inside our network.  My requirements are

[ul]
  • an internal firewall to prevent both incoming and outgoing traffic (incoming from other schools on the WAN and outgoing to prevent VPNs and other unauthorised traffic)
  • an internal proxy server (explicit proxy with an upstream proxy-chain) to provide better content filtering than provided by the district
  • ultimately we will setup VLANs for staff and students and so we will need some routing/natting[/ul]

    I have considered the following setups

    [ol]
  • one vdom with a virtual-wire pair and explicit proxy,
  • two vdoms.  the root vdom to do inter-vlan-routing and natting, and a secondary vdom in transparent mode to do the firewalling and proxy server[/ol]

    Any thoughts and suggestions would be greatly appreciated.

    Thanks in advance,

    Chris.

  • 0 REPLIES 0
    Labels
    Top Kudoed Authors