I have three ISPs (2x Comcast and ATT fiber) that I would like to share between mutliple internal VDOMs (corresponding to internal VLANs). Some of the VDOMs will route primarely over ATT, others might only use 2x Comcasts. Each ISP has public static IP pools that used to NAT egress traffic.
I know 5.6.3 introduced a virtual switch that allow to share a physical interface.
So far, I am considering the following two approaches:
1- a dedicated VDOM that handles 3 x ISP with SD-WAN and inter-vdom links connecting to the internal VDOMs.
2- a virtual switch where the internal VDOMs share physical interfaces connected to indivisdual ISPs.
What are the pros and cons for #1 and #2 architectual designs.
Thanks
OB
I was attending FortiGate training yesterday, and I've discussed this issue with a Tech from Chicago. His recommendation is to go with a dedicated VDOM with SDWAN and establish inter-VDOM links to allow other VDOM to get out.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.