Fortigate 1100VDOM Internet Access
Hi
I am new to Fortigates and currently looking to swap out our Cisco ASA HA Pair with a Fortigate Cluster. I am having a look at how best to design this. Currently we have a /29 point to point with the ISP. Then we also have a /26 public address block used for natting services. currently we only use a single context on the ASA.
I am looking to create 3 VDOMs all of which need internet access. What would be the best ways of achieveing this. Would you recommend the best solution to be to go hierarchical by having a 4th internet facing VDOM (root vdom) terminating the point to point to the ISP. Then for the 3 VDOMs to use the internet VDOM as their gateway. Or is there any other way of achieveing this.
The other thing I am trying to figure is our connection to the DMZ. We will have an interface on each firewall in the cluster connecting to the DMZ host via a switch. The DMZ is segregated into multiple VLANs, and the VLANs need to terminate on the different VDOMs. Can this be achieved so multiple VDOMs share the same physical interface using VLANs.
Thanks
