Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Collis
New Contributor

VDOM Vlink Multi tenant setup

Hi, I' ve been testing vlinks in a multi vdom setup but struggling to get traffic flowing (internet bound) from the customer to the management vdom (WAN connection here). I' m able to get this working when I use IPs on the Vlinks but not when i use 0.0.0.0/0.0.0.0 for the vlink addresses. Customer VDOM (port1) ->npu-vlink0-> Management VDOM-> WAN (port2) Customer VDOM: port1 -> npu-vlink0 (any any firewall rule) npu-vlink0 -> port1 (any any firewall rule) route table: 0.0.0.0/0.0.0.0 GW 0.0.0.0 (npu-vlink0) Management VDOM: npu-vlink1 -> WAN (any any firewall rule) WAN - >npu-vlink1 (any to any firewall rule) 192.168.0.0/24 (customer subnet) GW 0.0.0.0 (npu-vlink1) 0.0.0.0/0.0.0.0 GW <WAN next hop ip> (port2) Any ideas? I' m finding the documentation has errors which is not great :-( Thanks - Rob
4 REPLIES 4
Collis
New Contributor

Any hints and tips for this one - I' ve been hitting my head against a brick wall today
emnoc
Esteemed Contributor III

diag debug flow and diag sniffer are your friends? Did you do any diagnostics? How does each vdom route-table look like; get router info blah blah i would start with the above steps and double check routing info and then fwpolicies for traffic being allowed and from each vdlm to the other.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Collis
New Contributor

Thanks for the suggestions... I did use these commands but still struggled to find the issue. I decided to try changing the hardware accelerated vlink (npu0) to a normal vlink (cpu bound) and everything worked! Have you managed to get the hardware accelerated vlinks working? I' ll try again tomorrow just in case I’ve missed something stupid. Thanks again.
emnoc
Esteemed Contributor III

hardware accelerated vlink
Did you read this kb? http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD33888&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=52307756&stateId=0%200%2052309090 might shed light into your problems

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors