Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cdelarosa
New Contributor

VDOM Mode Split vdom

Hello, 

Im studying for the NS4 and i was wondering in what cases scenario is the Split VDOM Use

I could read that  it has to vdoms

the Root and one more

The root is for managment only work so i just actually get one vdom to work with.  Why i would like to use this mode if it just give me one vdom? 

I dont have too much experience with fortigates so i cant think in one, but i would like to know.

 

Cheers

Carlos

2 REPLIES 2
Toshi_Esumi
Esteemed Contributor II

Actually me neither. It's just to separate management vdom from user(root) vdom so that the user (vdom) wouldn't see any management traffic like FortiGuard access and others. But to me that's relevant if the entire chassis is owned/managed by somebody else other than the vdom users. If it's only for yourself, probably it doesn't matter much since all circuit(s) are for yourself including management use.

We do have shared chassis setups with multiple customer VDOMs, and we set a dedicated management vdom to carry the management or common service traffic. But that's different from the "split vdom" feature is intending.

lobstercreed

I tend to agree with Toshi that it's not an attractive feature, but I think there are two advantages perhaps (having not used it, just going off my understanding of it).

 

[ol]
  • It reduces the attack surface of the firewall by essentially creating "out of band" management -- especially useful for firewalls that don't have a dedicated management port.  Perhaps I'm wrong, and perhaps a similar thing can be achieved with proper hardening under 1 VDOM (I feel fine with my own settings).
  • It should simplify the configuration steps needed to ensure proper routing of management traffic.  Self-originated traffic does not use SD-WAN rules by default and even with ALL of knobs turned on per this document, some traffic still ignores SD-WAN depending on the features you're using (had a ticket open very recently about this).[/ol]