Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

DaveLeav
New Contributor

Two vDOM's, one WAN source...

I have a Fortinet running in a DC, I am looking at setting up vDOM's (I should have done at the start I know), I have a single internet presentation with 6 IP's into our untrust switch.  Can I setup two vDOM's that share the same WAN link?  The presentation would be two separate lines from the untrust switch but the WAN gateway would the same in each vDOM.

1 REPLY 1
ocarper_FTNT
Staff
Staff

Hi Dave,

Yes you may do so, you have to set at least 3 VDOMs: one root, VDOM1 and VDOM2 and then you have to configure interVDOM links.

In this scenario, Internet traffic should be routed through root VDOM, which is connected to the others via interVDOM links and only root VDOM is physically connected to the Internet. In this topology, the peer VDOMs (1 and 2) are only linked  with the root VDOM, not with each other.

Please review the following link, which shows a full example of the configuration you're asking for.

 

http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-virtual-domains/4-Inter-VDOM-routing/7-Example-configuration.htm#Example