Description |
This article describes a configuration that uses multiple VDOMs as HUBs sharing a single public IP address. A NAT VDOM is used to forward custom IPsec ports among the Customer VDOMs.
In MSSP-like or multi-tenant environments where different customers use a HUB and Spoke overlay topology, sharing a FortiGate HUB device, VDOMs are used to separate customers from each other. Each VDOM will operate as a HUB dedicated to a particular customer organization. Usually, in this scenario, each HUB will be reachable from the dial-up spokes pointing to a customer dedicated public IP address or FQDN. In some cases, the provider may need to share the public IP addresses, because the allocated IP addresses are not enough to cover their entire customer base on a 1:1 basis. |
Scope |
FortiOS: 7.0 and later:
|
Solution |
Follow steps 1 to 7 to configure the setup on FortiGate HUB:
See Configure Inter-VDOM link. Alternatively, a hardware accelerated vdom-link can be used: Configuring Inter-VDOM link acceleration.
config vdom edit customer01 current vf=customer01:4 config system settings set ike-port 45001 end
Reference: Configurable IKE port.
Reference: Virtual IP with services.
config system settings
Related articles: |