FortiManager multiple interfaces in each zone
Hi,
I just started a trial to evaluate the FortiManager product. I am using the latest 5.2 VM for the evaluation. I connected a 5.2.1 FortiOS. I did find out through the forum already that this FortiOS version is not support yet but I don't believe my problems are related to the FortiOS version. I am trying to accomplish the following with FortiManager:
For my test I am using 2 Fortigate firewalls with 2 Vdoms on each. Lets call them A1, A2, B1 and B2. They connect in the following way:
A1 – A2 – B1 – B2
A1 has 2 interfaces called A1-DMZ and A1-LAN.
B2 has 2 interfaces called B2-DMZ and B2-LAN.
I want to be able to create a firewall policy that goes from the interface on A1 to the interface on B2.
In order to do that I would need to map the source and destination zone in each vdom (A1-DMZ and A2-DMZ) . The issue is that there are multiple policies like this with different source and destination zones (A1+B2 DMZ + LAN). The system only allows me to map one zone to an interface. However interfaces that can connect to multiple zones due to them carrying traffic between vdoms are unable to be mapped to the correct zones. This means we are unable to map the correct zones.
I would need to map B2 LAN and B2 DMZ to the interface that goes from A1 to A2. This would allow the system to map the policy on that vdom to that specific link and then create the policy for it.
I am not sure if this is how FortiManager is supposed to work however I cannot see a different way to map the interfaces to zones in order to allow the firewall policies to be created through all the vdoms.
This is the first time I am using FortiManager so please correct me if I am wrong on any of the points.
Thanks, Andreas
