FortiNAC
L2 and L3 Network Types
            Version: 8.x
       Date: January 28, 2020
              Rev: A
                                1
FORTINET DOCUMENT LIBRARY
   http://docs.fortinet.com
FORTINET VIDEO GUIDE
   http://video.fortinet.com
FORTINET KNOWLEDGE BASE
   http://kb.fortinet.com
FORTINET BLOG
   http://blog.fortinet.com
CUSTOMER SERVICE & SUPPORT
   http://support.fortinet.com
    http://cookbook.fortinet.com/how-to-work-with-fortinet-support/
FORTINET COOKBOOK
   http://cookbook.fortinet.com
FORTINET TRAINING AND CERTIFICATION PROGRAM
   http://www.fortinet.com/support-and-trainingt/training.html
NSE INSTITUTE
   http://training.fortinet.com
FORTIGUARD CENTER
   http://fortiguard.com
FORTICAST
   http://forticast.fortinet.com
END USER LICENSE AGREEMENT
   http://www.fortinet.com/doc/legal/EULA.pdf
 Monday, September 10, 2018
                                                                      2
Contents
Overview ............................................................................................................................................... 4
Layer 2 .................................................................................................................................................. 5
Layer 3 .................................................................................................................................................. 6
                                                                                                                                                          3
Overview
This document explains the Network Types available when configuring FortiNAC. For more
information on appliance configuration, see the appropriate installation guide in the Fortinet
Document Library.
There are two network type options:
   •   Layer 2 network: Isolation networks are switched to the FortiNAC eth1 interface.
       802.1Q tags are configured for the corresponding isolation VLANs, and eth1 IP addresses
       are within those isolation networks. See Layer 2 for illustrations
   •   Layer 3 network: Isolation networks are routed to the FortiNAC eth1 interface. See
       Layer 3 for illustrations
       Important: In a High Availability environment with L3 configuration (redundant
       FortiNAC servers on different subnets and do not use a shared IP address), the Layer 3
       network option is required. L3 High Availability configurations are not supported with
       Layer 2 Isolation settings.
                                                                                                 4
Layer 2
          5
Layer 3