I am trying to determine the best design for VDOMs in a FortiGate that will be used to connect to multiple different customer sites via IPsec tunnels. Customers must be isolated from each other and I have more customers than the max 10 vdom limit, so a dedicated vdom for each customer is not an option. My plan is to have:
root vdom (Global shell)
mgmt-vdom (Fortigate mgmt functions and administration - type "Admin" vdom - has internet access via traffic-vdom)
traffic-vdom (has wan interface, function is to provide other vdoms wan/internet access)
customers-vdom (customers shared vdom, vpn tunnels for each customer)
vendor-vdom (third-party vendor for monitoring customer sites and providing access to vendors cloud applications - vpn tunnel to vendors cloud)
No LAN resources for customers, I am only handling traffic from customers to vendor via the IPsec tunnels.
What is the best and most secure way to configure vdoms and IPsec tunnels.
Inter vdom links from other vdoms to traffic vdom?
No vdom links, but using subinterfaces of the wan port for each customer. Wan located in traffic vdom, subinterfaces of wan located in customers-vdom.
Where to terminate vpns - all in traffic vdom? Or customer vpns in Customers vdom, Vendor vpn in vdom? etc.
Segregate by only using IPsec interfaces for each customer? Or both IPsec and Vlan interfaces?
How to best leverage hardware acceleration in the design
The more I research the more confused I become as to how to approach this.
Thanks
If link doesn't work, you likely have a network problem on your end.
Just use a search engine (I always use google) and type "fortigate how to use npu-vlinks". That's what I did with google to find the KB as well as some others.
Toshi
| User | Count |
|---|---|
| 2738 | |
| 1419 | |
| 812 | |
| 739 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.