- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Questions on VRF routing
We are preparing a conversion from a Firepower to a FortiGate 2600. This will be the second attempt due to some routing issues. This is an HA pair, and we're using port15 as the management port. It's currently using the same VRF as the other ports, so we want to change this one to a different ID. I just want to make sure VRF will function as intended, that is, if we there are routes to the same network, say 10.0.0.0/8, for both the management port (VRF 1) and the inside interface (VRF 0), that packets coming into a data interface (say outside interface on VRF 0) destined to 10.1.1.1 will not go out the management interface on port15. What about if the management interface has a more specific route? I'd still expect it not to work but want to confirm. Thank you.
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes VRF on FortiGate functions the same as any network device. Interfaces in a VRF will share a separate and dedicated routing table.
You can also use a special system command to manage this for you but it relies on VDOMs (virtual contexts). It's transparent to the admin but it will put the defined interface into a hidden VDOM called "dmgmt-vdom" with its own dedicated routing table. See here:
https://docs.fortinet.com/document/fortigate/7.2.0/cli-reference/26620/config-system-dedicated-mgmt
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes VRF on FortiGate functions the same as any network device. Interfaces in a VRF will share a separate and dedicated routing table.
You can also use a special system command to manage this for you but it relies on VDOMs (virtual contexts). It's transparent to the admin but it will put the defined interface into a hidden VDOM called "dmgmt-vdom" with its own dedicated routing table. See here:
https://docs.fortinet.com/document/fortigate/7.2.0/cli-reference/26620/config-system-dedicated-mgmt
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you. That's just what I needed.
