Skip to main content
amorales
New Member
April 8, 2021
Question

Enabling VDOM downsides

  • April 8, 2021
  • 6 replies
  • 7847 views
Hi, I am wandering if there is any downside due to enabling VDOMs in a FortiGate. As far I know, by default all VDOMs could make use of all firewall resources and there is no any limitation except if the admin configure them explicitly, but I just want to confirm if there is some limitations or constraints for enabling VDOMs compared to do not using them. I want to enable VDOMs to use the root VDOM just for management traffic, and create only one extra VDOM for production traffic. Thanks.

    6 replies

    emnoc
    New Member
    April 8, 2021

    Downsides? You mention it in resources limits. And you need to carefully think out what interface/port you assign to a vdom since it can only be in one.

     

     

    Now in your request this is done a lot where management is done via one vdom and production in the other. You should also think heavily on how the 2 will talk to internet( do you use emac-vlan, or a dedicated wan-port, or vdom-links, etc...)

     

    And lastly SDWAN is that something you need now or might need later ?

     

    Ken Felix

     

    amorales
    amoralesAuthor
    New Member
    April 9, 2021

    Thank you Ken. Yes, I am aware of VDOM configuration and I am keeping in mind how to talk to Internet from the root VDOM.

     

    On the other hand, if I have FortiManager, will the root VDOM also consume an extra license? Thanks.

    emnoc
    New Member
    April 9, 2021

    What do you mean extra license? All fortigates comes with up to 10vdom ( disregard the smaller units ) . Some are upgradeable to more vdom. Most none sml-to-medium enterprise models are fixed at 10vdoms. Until you. get into models 1000 or larger, vdoms are limited to 10, larger units have upgrade options.

     

    note: Fortimanager can managed a fgt with 1 ,2 , 3 or 10 vdom, nothing changes from it's perspective as a manager.

     

    FYI; Also Fortimanger has it "adom" limits also and device total managed # of devices but these are primary on the bigger managers.IIRC you can't update adom totals but total number of devices is a license option. Thank of adon as administration domains so you can partition a fmgr to allow admo-1 to managed only fgt#1,#2,#3, and adom2 can only managed fgts,#4,#5,#6

     

     

    Ken Felix 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!