thank you very much for reply, i understand now the purpose of vlink but i want to no if is it possible to pass snmp flow for exemple vdom internet to vdom root in order to monitor all equipement.
I have ipsecvpn mount on vdom internet, and i want to reach vdom root in order to monitor fortigate master/slave and fortianylser. The issue are by defaut the vlan management are on vdom root so how can i do ???
Best regard's and sorry i didn't have big experience in this technology
Not 100% following you, but I 'll clue you in ; "if the VDOM in question has the allowaccess "snmp" function and the interface is L3 addressable, than I would think you can enable snmp on the interface and in that vdom and monitor the fortigate."
Maybe it's my fault, i'm not clear actually we have ipsecvpn mount on vdom internet and i want to monitor some machine on vdom ROOT the issue is vlan management are by default on vdom ROOT.
Okay so you have a multi-vdom with "internet-vdom" terminating the VPN. You want to monitor/manager machines in another vdom? Right ?
if yes this is as simple as providing routing over the internet-vdom & a vdom-link and applying the correct fwpolicies. I don't see this as being a showstopper.
Just following my design with stack( meshed vdom ) and it should be clear. A vdom is a compartmentalize virtual firewall within the same hardware skin. routing and fwpolicies and of course the VPN allowing that traffic.
Sorry i don't understand very well have you a exemple ? this is how the cluster fw are configured, it's cluster fortinet 1000 with vdom internet & vdom root,"internet-vdom" terminating the VPN On vdom internet : vip fw-cluster-1 / mgmt1 192.168.0.2 mgmt2 192.168.0.4 wan1 68.55.0.3 vip fw-cluster-1 / mgmt1 192.168.0.2 mgmt2 192.168.0.4 wan1 68.55.0.3 vip fw-cluster-2 / mgmt1 192.168.0.3 mgmt2 192.168.0.4 wan1 68.55.0.3 On vdom ROOT :
The vdom management by default are on vdom ROOT here 192.168.0.0/24, how i can reach and monitor equipment on vdom ROOT through vdom internet where we have the ipsecvpn mount on it.