So the security fabric functions are currently not supported on devices running with VDOMs enabled.
Has anyone heard any info on when this is going to be fixed?
You would think that a function that is designed to help multiple devices work together would be supported on devices that within the same chassis have multiple firewalls that need help working together! It doesn't seem like it is too much of a stretch to make it work- just set fabric settings per VDOM and treat every VDOM as a unique device (just like they are intended). I know it's not an API problem because the API is totally capable of handling multiple VDOMs. At this point the only thing the fabric function does with VDOMs is allow you to offload traffic to a FortiWeb/Mail/Sandbox device for further inspection. This is really annoying!
CISSP, NSE4
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I must say I was disappointed to discover you cannot use the Security Fabric on a FortiGate where a VDOM is in use :(
I would say this is a rather big over site and i am surprised there are not more comments on this page.
Make sure to request Security Fabric VDOM support from your Fortinet contacts.
Makes it more likely we'll actually get it one day.
I just spent some hours trying to discover why there are no Security Fabric options .. here i found the solution - we use vdoms on every FW...
This should definitively be possible!
I'm very disappointed for this. In FortiOS 6.0.0 same limitation.
NSE 7
This is very strange they are saying that you should configure security fabric in your edge device but it should not have VDOM enabled then what is the use of security fabric. Of course, security fabric will not enable the branch device. It's really annoying. I think Fortinet should think about this seriously. At one point they marketing that they are having security fabric where other does not have.
CCIE-Security, CISSP, CEH, CCNP, CCNA, FCSNSP, CCSA, ACE, JNCIS-security, MCSA, MCP
I'm deeply disappointed that vdoms are not supporting CSF, I don't really understand why Fortinet Sales are putting so much effort on something that most of the deployments won't support(In my case 80% of installations have vdoms enabled..)
Hi,
in 6.0.x I have the "Security Fabric" menu in every VDOM.
Some of the Security Fabric Features are only listed in the Global Section.
Regards
bommi
NSE 4/5/7
6.0.x has the same problem as the other versions. You see the security fabric menu. When you try to enable it with VDOMs turned on, the only items you can do is offload scanning to dedicated devices. You do not have the option of enabling fortitelemetry between fortigate devices. The documentation clearly states that security fabric is not supported on devices with VDOMs enabled.
For what it's worth, i have ended up re-architecting in a way that I need less VDOMs overall. I'm on a path to remove the need for VDOMs based on current usage without actually needing to buy more firewalls. The primary driver was for easier management, but the ability to see all the traffic in the FGT interface with the telemetry going between devices is a plus.
CISSP, NSE4
Hi Bommi,
yes, even in version 5.6 you have the menus for Security Fabric but apart of showing the Topology, you can not enable the useful features to have visibility of your Fortinet devices and the Security Audit. That is due to the vdom limitation for CSF.
Regards,
Walvis
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.