Hi guys,
I' m new to Fortigate and am trying to setup a pair of 100D (running 5.00b147) in HA cluster for use in our datacentre. I' m learning about VDOMs, HA, VLANs etc. as I go so if these are basic questions please forgive me!
The goal is to end up with the two 100D firewalls in some form of HA cluster, connected to the datacentre ISP on the WAN side and to a set of VLANed switches on the LAN side.
My plan was to set the 100Ds up in a active/passive HA cluster, create two VDOMs (there are two separate companies sharing the firewalls and switches) and enable VDOM partitioning (virtual clustering) to spread the two VDOMs (and the root) across the two 100Ds. This seemed like the perfect scenario as it allowed us separate the two companies from an admin point-of-view and gave us HA while also utilising the resources of both 100Ds.
I got most of the above configured and tested but then came across two issues -
1. I had assumed I could " share" the WAN interface between the two VDOMs, (they' ll both have their own ranges of public static IP addresses but probably just one WAN uplink port to the ISP). On reading more though I think I need to basically route the traffic through the root VDOM, which seems a bit cumbersome when we don' t really want to do any " control" of the traffic at the root/management level. Am I understanding this correctly or could VLANs be used here in some way?
2. The two customer VDOMs don' t necessarily HAVE to communicate with each other, but it would be good to have the option, so an inter-VDOM-link is required however I read this line in the admin guide " With virtual clusters (vclusters) configured, inter-VDOM links must be entirely within one vcluster" . So if I' m reading this correctly I cannot setup an inter-VDOM link between the two customer VDOMs because I am using VDOM partitioning? Assuming I' m reading that right, I then don' t understand how I will be able to route both of my VDOMs' traffic through the root VDOM given that the root VDOM will be on one vcluster only, so the customer on the other vcluster will not be able to have an inter-VDOM link.
Maybe it' s just too late at night and I' m confusing myself but some guidance would be much appreciated!
Thanks