Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
3xit
New Contributor

Network design - need help

Hi all,

 

I would need your help in choosing the proper network equipment for my network project.

A company that I work in has a very old network and they asked me to write a project where we would replace the whole network. They use this network just for some basic stuff, surfing, etc., not for real work but need to be stable and safe. Since they have a lot of Cisco 3750G and 2960S switches, we can use them in the first phase and budget to use for the purchase of a firewall.

Here is what we have: - two BO connected to HQ over 1 Gbps dark (metro) fiber and one of these two has an additional 100 Mbps internet connection - one BO connected through 100 Mbps MPLS (probably will be replaced with the internet instead of MPLS) - ten BO connected to the internet (they are not imported but would be good to have them routed through the same network in feature)

At this point, we need hardware where we can connect two BO over dark fiber and one over MPLS to HQ. Also, HQ will have around 20 access switches and probably two or three distribution switches. In the second phase, sometimes in feature, we will add other BO to this network so the hardware should support it. We will have one server where we will add the Windows VM server to work as DHCP, DNS, AD, etc. We need multiple VPNs, multiple VLANs...

I was thinking of something like this:

HQ: Main firewall - FortiGate 400E - He would be connected to the main internet line, two dark fiber lines, one MPLS, and one for distribution switch for HQ Distribution switch - 3750G - He would connect to FortiGate, server, and access switches Do we need a router? (I mean, FortiGate can create VLANs and make VPNs, routing, etc. so my question is do we need ex. Cisco 4321 router?)

BO: two BO which goes through dark fiber would be FortiGate 100F with VPN connection another BO which goes through MPLS would use FortiGate 80F

Since we have a server, distribution, and access switches, we will need to purchase a firewall and eventually some additional equipment. Knowing management and how they decide, I will probably need to make two variants for this project so one will be expensive and another one will be "normal" that I prefer to have. Better to not mention that we can go with a lower price, you know what I mean :) Currently, we are paying a little bit over $2000 for support with one firewall we have and no one at our company likes it. We just want to get rid of it and change to FortiGate. Also, Management wouldn't be happy if they need to pay for support more than $4-5k yearly so I have to watch out for support that goes with FortiGate. Maybe take support just for the main firewall at HQ and not for BO?

 

Any suggestion would be much appreciated! In the next two weeks, I have to write roughly how much the project would cost. At this point, it is really hard to say how big is the budget for this project. I would separate HQ and BO so if they don't approve all at the same time, I want to get at least HQ so that I can start replacing that network. Since they don't have any VPN at the moment it shouldn't be a too big problem and there is no too much configuration on the current firewall and switches. This is an opportunity to make it properly! 

0 REPLIES 0
Labels
Top Kudoed Authors