Hi everyone! First post here, so please bear with me if I'm asking something obvious. I've been tasked with setting up a secure guest network at our small office using our FortiGate 60F. I've got admin access and have done some basic config, but VLANs and firewall policies are still new to me.
I understand the concept: isolate guest traffic from our internal LAN. But I'm feeling a bit overwhelmed by the actual steps in FortiOS. I want to make sure I don't accidentally leave a security hole.
Could someone walk me through the process from start to finish? I'm especially fuzzy on:
- The correct order of operations (VLAN interface first, then SSID, then policies?)
- How to properly set the addressing for the guest network.
- The specific firewall rules needed to allow guest internet access but block attempts to reach internal IPs.
- Any recommended security profiles for this kind of traffic.
A checklist or a plain-English explanation would be incredibly helpful. We're not using a guest portal or anything fancy yetβjust basic password-less access for now. Thanks in advance for your patience! 😅