Hello,
I have question when configuration Dedicated Management interface for my firewall.
Should I put it to root VDOM? or I should create another new VDOM and assign it there? or another better practice?
Thanks!
It wouldn't be a matter if the purpose of the mgmt interface(s) is to get in the unit out-of-band with a super-user admin. We leave them in the default root vdom.
Then the others ports like WAN is better to split into another VDOM?
One reason is if mgmt interface is using different path compare with WAN port to access Internet.
Another reason is better to manage.
Mgmt interfaces can't be used to carry user traffic. It wouldn't even show up in routing table. You probably saw (didn't see) in root vdom by now. It's dedicated to management purpose only. All the other ports can be used for any routings&firewallings, which you might want to move around vdoms depending on your network design with multiple vdoms.
Here is a KB explaining best practice for the management interface http://kb.fortinet.com/kb/viewContent.do?externalId=FD37035
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1738 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.