Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
albaker1
Contributor

Questions on VRF routing

We are preparing a conversion from a Firepower to a FortiGate 2600. This will be the second attempt due to some routing issues. This is an HA pair, and we're using port15 as the management port. It's currently using the same VRF as the other ports, so we want to change this one to a different ID. I just want to make sure VRF will function as intended, that is, if we there are routes to the same network, say 10.0.0.0/8, for both the management port (VRF 1) and the inside interface (VRF 0), that packets coming into a data interface (say outside interface on VRF 0) destined to 10.1.1.1 will not go out the management interface on port15. What about if the management interface has a more specific route? I'd still expect it not to work but want to confirm. Thank you.

1 Solution
gfleming
Staff
Staff

Yes VRF on FortiGate functions the same as any network device. Interfaces in a VRF will share a separate and dedicated routing table.

 

You can also use a special system command to manage this for you but it relies on VDOMs (virtual contexts). It's transparent to the admin but it will put the defined interface into a hidden VDOM called "dmgmt-vdom" with its own dedicated routing table. See here:

 

https://docs.fortinet.com/document/fortigate/7.2.0/cli-reference/26620/config-system-dedicated-mgmt

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-dedicated-mgmt-feature-Out-of-ba...

 

Cheers,
Graham

View solution in original post

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards

Anthony-Fortinet Community Team.
gfleming
Staff
Staff

Yes VRF on FortiGate functions the same as any network device. Interfaces in a VRF will share a separate and dedicated routing table.

 

You can also use a special system command to manage this for you but it relies on VDOMs (virtual contexts). It's transparent to the admin but it will put the defined interface into a hidden VDOM called "dmgmt-vdom" with its own dedicated routing table. See here:

 

https://docs.fortinet.com/document/fortigate/7.2.0/cli-reference/26620/config-system-dedicated-mgmt

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-dedicated-mgmt-feature-Out-of-ba...

 

Cheers,
Graham
albaker1

Thank you. That's just what I needed.

Labels
Top Kudoed Authors