Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Downsides? You mention it in resources limits. And you need to carefully think out what interface/port you assign to a vdom since it can only be in one.
Now in your request this is done a lot where management is done via one vdom and production in the other. You should also think heavily on how the 2 will talk to internet( do you use emac-vlan, or a dedicated wan-port, or vdom-links, etc...)
And lastly SDWAN is that something you need now or might need later ?
Ken Felix
PCNSE
NSE
StrongSwan
Thank you Ken. Yes, I am aware of VDOM configuration and I am keeping in mind how to talk to Internet from the root VDOM.
On the other hand, if I have FortiManager, will the root VDOM also consume an extra license? Thanks.
What do you mean extra license? All fortigates comes with up to 10vdom ( disregard the smaller units ) . Some are upgradeable to more vdom. Most none sml-to-medium enterprise models are fixed at 10vdoms. Until you. get into models 1000 or larger, vdoms are limited to 10, larger units have upgrade options.
note: Fortimanager can managed a fgt with 1 ,2 , 3 or 10 vdom, nothing changes from it's perspective as a manager.
FYI; Also Fortimanger has it "adom" limits also and device total managed # of devices but these are primary on the bigger managers.IIRC you can't update adom totals but total number of devices is a license option. Thank of adon as administration domains so you can partition a fmgr to allow admo-1 to managed only fgt#1,#2,#3, and adom2 can only managed fgts,#4,#5,#6
Ken Felix
PCNSE
NSE
StrongSwan
Ken,
I'm afraid you may be mistaken when you say nothing changes from the FMG perspective with multiple VDOMs. I have a single HA pair of FGTs that have 3 VDOMs and consume 3 licenses on FMG. That's also what our SE told me when he sized our FMG licensing.
So yes, Arnaldo, your concern about licensing is valid. I'd be happy to be proven wrong. - Daniel
@Ken - what the OP meant was licenses on the FMG side, and as Daniel mentioned already - yes, each additional VDOM on the managed by FMG FGT will use up additional license out of total paid for.
@amorales May be split-vdom - when one VDOM is for management only will not eat up separate license ? Just thinking out loud.
Okay yes that is correct each vdom is going to consume a license. So you have to determine how many fortigates , how mnay vdoms total and then go with that number and growth.
keep in mind buying add-ons can get to pricey.
E.g
add a 10 add-on 10 times, would cost 2x more than buying a 100 add-on just one time
I would speak to the sales team if are using or planning fmgr to see what discounts you can leverage but YMMV.
Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.