Skip to main content
yw2023
New Member
March 24, 2023
Solved

Connecting Fortigate(Multi VDOM) and Fortianalyzer

  • March 24, 2023
  • 10 replies
  • 9675 views

 

Hi All,

 

FortiGate600E (HA) and FortiAnalyzer200F are connected.
The FG has a 2 VDOM. (I don't use "root".)
VDOM1 is the main network and is also used for management.
VDOM2 has a separate network.

Both are connected to the Internet by separate lines.

 

FA is on the VDOM1 side and is logged by VDOM1.
I want to get this with FA for VDOM2 logs as well.
However, VDOM2 cannot access VDOM1's network.

 

What solutions are possible?

 

 

- The way I come up with it.
1. Set up connection to FA with Global, not VDOM1.
2. Enable "set use-management-vdom" in "config log fortianalyzer override-setting" in VDOM2
(This also sends the VDOM2 logs to the FA via the VDOM1 interface, am I correct?)
3. Enable communication from VDOM2 to VDOM1 using VDOM link

 

- Proposals claimed by others.
4. Physically wire and connect from Switches connected to VDOM2 to FA
(In this case, the second port of FA needs to be connected)


Plan 3 has been confirmed to be doable.
I think plan 2 is a reasonable one.
However, since there is only one FA, I think the original form would be to set it up in Global of Plan 1, not in each VDOM.

 

I think plan 4 is wrong.
The person who proposed this plan says that Plans 2 and 3 are a last resort, to be done when there is no other way.
(For me, this is the last resort).

 

What is the most appropriate means?

Best answer by gfleming

If you change to global it's a very minor change. You'll possibly lose a few logs as things switch over on the FAZ side. That's about it. I would suggest you just enable FAZ on the global setting that would be easiest for you.

 

You can also try the "use-management-vdom" setting which sounds like it will accomplish something similar.

 

You don't need to add any interfaces to the FGT. You already have all of your physical connectivity. We are talking about logical connections now. (Unless you are thinking about the option to add an interface to FAZ for connectivity into VDOM 2. But that doesn't need a new intf on the FGT).

 

 

10 replies

gfleming
Staff
Staff
March 24, 2023

Definitely use VDOM links. This will be easiest and most secure way of doing it.

Or put an second interface of the FAZ into VDOM 2 network and go direct to it.

 

EDIT: @funkylicious has the right answer below

yw2023
yw2023Author
New Member
March 25, 2023

Thanks Graham.

 

Why is VDOM Link definitively?
Is there an overall setting or "use-management-vdom" that should not be used or is it a different feature?
I am having a hard time finding documentation that explains these.

 

 

gfleming
Staff
Staff
March 27, 2023

Sorry I was misinterpreting your question. @funkylicious has the right answer. You don't need to do anything special. The FortiGate will send all VDOM logs to FortiAnalyzer from the main link.

yw2023
yw2023Author
New Member
March 27, 2023

No problem.
Just for reference, I would like to ask.
If we just can't make it to the global setting, is it a VDOM Link (Plan 3) or a physical connection (Plan 4)?

Is use-management-vom(Plan2) misplaced?

 

Also, would the order of priority for consideration be Plan 1 through Plan 4?

funkylicious
SuperUser
SuperUser
March 25, 2023

You could enable FAZ globally which means that you will send all the VDOM logs through your management VDOM, then in FAZ you can move to ADOMs the VDOMs if you want.

There is no need to do an override if this is what you want to achieve.

"jack of all trades, master of none"
yw2023
yw2023Author
New Member
March 27, 2023

thanks @funkylicious

 

Normally, I would agree with you.
Even though there are two virtual devices, there is only one target to manage.
I wish you had done it globally when you connected FG and FAZ when you built it...
(Plan1)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!