Created on
03-26-2021
01:23 AM
Edited on
05-27-2025
01:10 AM
By
Jean-Philippe_P
Description
This article shows that it is necessary to use management VDOM to communicate to FortiAnalyzer on FortiGate settings.
Scope
FortiGate.
Solution
Diagram.
The 'FAZ_VDOM' on FortiGate has a direct connection to FortiAnalyzer.
But in this scenario, the management VDOM is the 'ROOT VDOM'.
With that, if the fabric connector is configured for FortiAnalyzer on FortiGate, it will automatically use the root VDOM to reach the FortiAnalyzer, which will fail.
Image 1 shows that the root VDOM is the management VDOM.
If the approach here is to change the source IP of the FortiGate FortiAnalyzer setting using IP of 'FAZ_VDOM' that will not work because the management VDOM is still the root VDOM.
Here is an image for that:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.