I've got a couple of VDOMs set up using a shared internet connection through Root. Root has to have firewall policies to allow/foward/nat the traffic from the VDOMs to the internet. I will have the security profiles implemented at the individual VDOM level so does it make any sense to have the same security profiles enabled on the Root VDOM firewall rules? Seems to me like it would just be wasting system resources. Basically would be checking traffic that's already been checked. Thoughts? I'm thinking no security profiles at the Root VDOM, just rely on the individual VDOMs security profiles.
Solved! Go to Solution.
I would agree to your idea. In your set up, the root vdom is a separate NAT router in front of FW(vdom)s. We do NAT in multivdom setup (vdom per customer) at customer vdom, where each customer has own public IP(s). So root vdom is just an internet router routing public IPs from/to internet to/from all vdoms. There are only two policies in root vdom with zones in-to-out and out-to-in without any inspection.
Toshi
I would agree to your idea. In your set up, the root vdom is a separate NAT router in front of FW(vdom)s. We do NAT in multivdom setup (vdom per customer) at customer vdom, where each customer has own public IP(s). So root vdom is just an internet router routing public IPs from/to internet to/from all vdoms. There are only two policies in root vdom with zones in-to-out and out-to-in without any inspection.
Toshi
Thanks, good to know I'm not not only one thinking that.
you can use the security profile in the internet facing vdom where wan interface are part of and yes the same traffic is not required to do multiple inspection in each vdom as it will be resource intensive
Yeah, in this case the inspection will be done at the "sub-VDOM" level and the Root VDOM will just pass the traffic without any inspection.
you are correct IrbkOrrum
Hi @IrbkOrrum ,
If you have applied Security Profiles at VDOM level, there is no need to apply them again in the root VDOM.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.