Skip to main content
Mo1982
New Member
December 23, 2020
Question

Fortigate 1101 VDOM Design

  • December 23, 2020
  • 0 replies
  • 1886 views

Hi

 

I am new to Fortinet's and currently looking to replace our current firewalls with Fortigates. I have drawn up a quick topology (attached) to picture what I may be trying to achieve but have some questions around it. We require 3 VDOMS, to segregate WIFI, Corporate, and although most DMZ networks will trunk into the Corporate VDOM, there is one that needs to be separate for business purposes.

For external IPs, we have a P2P to the ISP, but we also have a /27 public IP block used for natting services.

 

My questions are:

1. Is it a good idea to have a 4th internet VDOM which is the root VDOM, I cant think of another way because of the fact we have a P2P to the ISP, then a separate block for natting

2. For policies and natting, I am thinking of doing all natting on the Internet VDOM, as well as having the policy for incoming traffic from outside

3. Use only firewall policies on the other 3 VDOMs and leave natting on the internet VDOM

4. For inspection would you recommend doing inspection of all 4 VDOMs

 

As I said, this is my first experience with Fortigates so there may be other ways I have not thought of and hoping someone can advise.

 

Many Thanks

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!