Most breaches don't spread through the firewall. They spread underneath it.
A perimeter firewall inspects traffic moving in and out of the network. Once an attacker lands on a single device inside, the next hop is usually another internal device on the same VLAN, and that traffic never touches the firewall at all. The switch forwards it at wire speed, with no questions asked.
That gap explains why network access control belongs at the switch port, not just at the edge.
The Traffic Your Firewall Never Sees
Take a typical office floor. Laptops, VoIP phones, printers, and IP cameras share one or two VLANs. A compromised printer sits a single Layer 2 hop away from every workstation in the building.
When malware on that printer scans the subnet, the switch treats it as normal traffic. No policy blocks it, and nobody logs it. The firewall sees nothing because the packets never leave the VLAN.
Attackers count on this. Once they're inside a flat network, they move laterally, harvesting credentials and mapping servers, long before they attempt anything the perimeter would catch. Printers, cameras, badge readers, and building management systems make ideal footholds. Nobody patches them often, they rarely run endpoint agents, and they almost always sit on the same network as the users.
Three Consoles, Three Policies, No Shared Context
The security gap has an operational twin. In most enterprise LANs, the firewall, the switches, and the wireless controller come from different vendors or different product lines. Each has its own console, its own policy model, and its own idea of who a device is.
The results are predictable. VLAN definitions drift between the switch stack and the firewall. A trunk port carries more VLANs than anyone intended. The wireless team assigns a guest SSID to a VLAN that the security team thought was isolated. When an incident hits, three teams troubleshoot three dashboards, and nobody can answer the first question fast: what is this device, and where is it plugged in?
When IT Builders engineers assess an enterprise LAN, they regularly find exactly this: user devices, printers, and IP cameras sharing the same broadcast domain, managed from separate consoles that each hold part of the picture. The network runs. It just runs without any real control over who talks to whom.
Do You Know What's Plugged Into Your LAN?
Effective port-level access control starts with an accurate device inventory and a clear view of how your VLANs, switches, and wireless actually connect.
What Port-Level Access Control Changes
Port-level NAC moves the security decision to the moment a device connects. Before the switch forwards a single frame of user traffic, it identifies the device and decides where that device belongs.
Identification works in layers. Devices that support 802.1X authenticate with certificates or user credentials. Devices that can't, such as printers, cameras, and most IoT hardware, fall back to MAC Authentication Bypass combined with device profiling, which fingerprints the device by its traffic and attributes. The switch then places each device on the right VLAN automatically, applies the right policy, and logs the decision.
An unknown device gets nowhere near the production network. It lands in a restricted onboarding or quarantine segment until someone classifies it.
In Saudi Arabia, this approach also supports the asset visibility and network segmentation that the NCA's Essential Cybersecurity Controls (ECC-2:2024) expect of regulated organizations.
How FortiLink Collapses the Stack
Fortinet approaches the LAN differently from traditional campus vendors. Instead of treating switches and access points as separate systems, FortiGate manages them directly.
FortiLink turns the FortiGate into the controller for FortiSwitch. Engineers define VLANs, port policies, and NAC rules once, in the FortiGate interface, and the switches inherit them. The same FortiGate also acts as the wireless controller for FortiAP. One policy engine now governs the firewall, the wired access layer, and wireless.
That consolidation unlocks three capabilities that are hard to build across separate products:
| Capability | Traditional Multi-Console LAN | FortiGate-Managed LAN (FortiLink) |
|---|---|---|
| Device onboarding | NAC rules on a separate server, synced to switches | NAC policies defined on the FortiGate, applied at the port |
| East-west control | Traffic within a VLAN flows freely through the switch | Intra-VLAN traffic can be blocked at the switch and forced through the FortiGate for inspection |
| Incident response | Analyst finds the device, then asks the network team to shut the port | Security Fabric automation quarantines the device at its switch port or AP when a compromise indicator fires |
The middle row matters most for lateral movement. When direct device-to-device traffic has to pass through the FortiGate, IPS and application control apply to internal traffic the same way they apply at the perimeter. That compromised printer can no longer scan the floor.
The Trade-Offs to Plan For
Forcing east-west traffic through the firewall adds load to it. Size the FortiGate for internal inspection, not just internet traffic, or you'll move the bottleneck instead of removing it.
FortiLink also requires FortiSwitch and FortiAP. For organizations mid-way through a switch lifecycle with another vendor's hardware in place, FortiNAC provides device visibility and access control across mixed-vendor environments, and FortiLink can follow at the next refresh.
What a Phased Rollout Looks Like
Nobody should switch on port-level enforcement across a campus in one weekend. A safer rollout runs in stages.
The first stage is visibility only. NAC runs in monitor mode, profiling every device that connects without blocking anything. This phase usually surfaces devices nobody knew existed. Once the inventory is clean, the team defines device groups and the segments each group belongs in.
Enforcement then starts with low-risk, well-understood groups such as corporate laptops on 802.1X, before extending to printers, cameras, and building systems. Each wave gets a rollback plan and a window for the helpdesk to catch misclassified devices. Automated quarantine goes live last, once the team trusts the classification.
From Flat Network to Controlled Access
A perimeter firewall on its own can't stop an attacker who's already inside a flat LAN. Stopping lateral movement means identifying every device at the port, segmenting by what the device is, and inspecting internal traffic where the risk justifies it. Managing all of it from one policy engine removes the drift that fragmented consoles create.
IT Builders is an authorized Fortinet Engage Partner holding the Secure Networking: LAN specialization. Our engineers profile existing LANs, design segmentation around how the business actually operates, and run staged NAC rollouts that tighten control without cutting off the devices people depend on.
Planning a LAN refresh or a NAC rollout?








