Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
Switching, wireless, WAN edge and access control

Network Security

The Security Fabric past the firewall. FortiSwitch and FortiAP managed straight from FortiGate with no separate controller, plus LTE/5G WAN edge, network access control, DDoS mitigation and voice.

Where to start

This is the Security Fabric past the firewall — the switching, wireless, WAN edge and access control that the FortiGate manages directly rather than through a separate controller and a separate console.

The consolidation is the point rather than a bonus. A FortiSwitch port becomes an object the firewall can write policy against, so a device that fails a posture check can be quarantined to a VLAN automatically without deploying a separate NAC product. Wireless traffic is inspected under the same policy set as wired, so there is no second security posture to maintain or to drift.

The common sizing error here is the uplink. A WiFi 6E or WiFi 7 access point will saturate a gigabit port on its own, so feeding modern wireless from a 1 Gbps access switch spends money on a bottleneck. Match the switch tier to the access points you are buying, not the ones you are replacing.

Decide these first

Are you buying wireless, wired, or both?

If both, specify them together. The PoE budget and uplink speed of the switch are determined by the access points, and quoting them separately is how a site ends up with switches that cannot power its APs.

What is your total PoE draw, not port count?

Budget runs out before ports do. WiFi 6E and 7 access points can pull 40 W or more each, and a switch advertising PoE on every port rarely powers every port at maximum simultaneously.

How many devices can you not put an agent on?

Cameras, badge readers, clinical devices and industrial controllers are where FortiNAC earns its place. If you cannot produce a list of what is connected, that is the argument for it.

Is cellular a backup or a primary path?

For failover, a single LTE FortiExtender is enough. If cellular is the primary uplink, dual-SIM across two carriers is the difference between a resilient site and one that fails with its carrier.

Browse network security