Ok.. I think I get it.
So, when i first set up the Fortigate and used the Wizard, I created the subnet that I then added the switch and access points to.
Now I am adding 3 seperate subnet interfaces in the fortigate for each of the areas
On the switch, I would only have ports tagged to the vlan that I need it to communicate with. So since I want wireless access, the 2 ports where the AP plug into would be tagged in each VLAN that needs to use the AP. Within the AP I can tag each SSID I create to only work with that specific VLAN.
I would take a separate port from the fortigate to each VLAN I build (or could I tag the one port for all VLANS?)
I would set firewall ans security rules and policy in the fortigate for each VLAN.
Now, if I could only upload a beer...

So, when i first set up the Fortigate and used the Wizard, I created the subnet that I then added the switch and access points to.
Now I am adding 3 seperate subnet interfaces in the fortigate for each of the areas
On the switch, I would only have ports tagged to the vlan that I need it to communicate with. So since I want wireless access, the 2 ports where the AP plug into would be tagged in each VLAN that needs to use the AP. Within the AP I can tag each SSID I create to only work with that specific VLAN.
I would take a separate port from the fortigate to each VLAN I build (or could I tag the one port for all VLANS?)
I would set firewall ans security rules and policy in the fortigate for each VLAN.
Now, if I could only upload a beer...
