Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

TimMcKe
New Contributor

Split VDOM

Is it possible to have IPSec VPNs that split between 2 VDOMs like Cisco tunnels?  I need to have many tunnels using a public interface in the 'root' VDOM, but routing/terminating in a different VDOM...

1 Solution
RolfStan
New Contributor

If I understand your question right. You are having 2 VDOM. The first one which is the root VDOM which is connected to the public Interface and the 2. one which is the VPN VDOM and that is connected to the 1. one via inter VDOM-link. Is this correct?

If so, you need a public IP on the inter VDOM-link of the 2. one. Alternate you can have this public IP one the 1. one as a VIP and forward the traffic to a private IP on the inter VDOM-link to the second VDOM.

View solution in original post

2 REPLIES 2
RolfStan
New Contributor

If I understand your question right. You are having 2 VDOM. The first one which is the root VDOM which is connected to the public Interface and the 2. one which is the VPN VDOM and that is connected to the 1. one via inter VDOM-link. Is this correct?

If so, you need a public IP on the inter VDOM-link of the 2. one. Alternate you can have this public IP one the 1. one as a VIP and forward the traffic to a private IP on the inter VDOM-link to the second VDOM.

TimMcKe

Yes, I could do it this way, but I would prefer to keep the two VDOMs isolated from each other. In the Cisco and Juniper worlds you can create a VPN tunnel with the physical interfaces in one VRF and the logical tunnel interfaces in a different VRF.


This would 1) simplify policy setup and 2) allow for small remote office cases where only one public address is allowed.


Tim McKee

________________________________
From: Rolf Stange via VPN:
Sent: Thursday, January 25, 2018 12:52:59 AM
To: vpn@lists.fusecommunity.fortinet.com
Subject: [VPN:] - RE: Split VDOM


If I understand your question right. You are having 2 VDOM. The first one which is the root VDOM which is connected to the public Interface and the 2. one which is the VPN VDOM and that is connected to the 1. one via inter VDOM-link. Is this correct?

If so, you need a public IP on the inter VDOM-link of the 2. one. Alternate you can have this public IP one the 1. one as a VIP and forward the traffic to a private IP on the inter VDOM-link to the second VDOM.

-----End Original Message-----
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.