Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Gijs
New Contributor

Fortilink - VDOM - managed fortiswitch - share switch amongst different vdoms

Hi,

 

I'm a bit stuck and I hope you can help me out.

We have more or less this setup (see image in attachment - setup.jpg)

 but the internet is patched on the 'distributed FSWs' because the ISP is a single interface (so when there is a failover in the fortigate HA cluster, there is no impact).

The fortiswitches (distribution and access layer) are uplinked through a FortiLink interface and the management of all the switch ports is done in the Fortigate.

 

Now, we would like to implement VDOMs, but using the same client switches (and thus the same Fortilink)

I have created a new vdom called test, but I don't understand how I can create a new vlan in vdom test and assign this vlan to one of the ports on the fortiswitches.

The existing fortilink is available in the root vdom, where I can manage all the switches and assign a vlan to a port on one of the switches.

I noticed that I can create a new vlan on the existing Fortilink in the global settings. This vlan is available in the test vdom (so I can use it and create some policies) but I cannot assign the vlan to a physical port on one of the switches in the root vdom.

So here I'm stuck...

Can you help me out on this ?

 

Thanks

 

Gijs

1 REPLY 1
simonorch
Contributor

an old'ish post but i was struggling with this last night.

you have to configures things in cli but be aware there are restrictions in what you can do with ports and vlans in a multi-vdom scenario, like no mclag for example. The basics of a simple port exported to another vdom seems to work, but start trying to combine lag's with different vdoms and i just could get it to work, at least not with the time i had. That's a major problem if you trunk to third-party switches.

And to top it all, whilst the exported ports appeared in the gui within their respective vdoms in 6.4.4, they disappeared in 6.4.5 which means the vlans configured to the non root vdoms are 'invisible' in the FG gui.

 

https://docs.fortinet.com...multitenancy-and-vdoms

NSE8
Fortinet Expert partner - Norway

NSE8Fortinet Expert partner - Norway
Labels
Top Kudoed Authors