Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

VDOMS and VLINK interfaces?

Could someone tell me the point of vlink interfaces? In particular I would like to know how you would set them up and link them to a root vdomain that is connected to the internet?
5 REPLIES 5
doshbass
New Contributor III

By default when you set up a VDOM, you assign physical interfaces to it. One Physical interface cannot be in more than one VDOM, hence there is no communication between VDOMs without comming out of one physical interface and back into another. Then came along VLINKs. VLINKs are a logical interface that exists between VDOMS. Currently they can only be configured using CLI. Once they are configured you treat them exactly as any normal interface. Check out http://docs.forticare.com/fgt/techdocs/FortiGate_VLANs_and_VDOMs_Guide_01-30004-0091-20070308.pdf for information on how to set them up.
Still learning to type " the"
Still learning to type " the"
Not applicable

Okay, I' ve been reviewing that document for a few days, but i' m still confused. I' m interested in setting up a managed vdom setup. I have 1 interface connected to the internet feed and 3 different vdoms. Each of those vdoms uses a different vlan interface? Would i be-able to make that work? Or do i need to setup sub interfaces on the external interface? and associate them with each of my different vdoms ?
doshbass
New Contributor III

Hi Scott, sorry about the time I missed your response. It all depends on what you want to do. As per your idea, you could create multiple VLAN subinterfaces and assign each sub interface to a VDOM. This means you would need to create multiple VLANS on your internet connection. Can you do that easily? If it were my setup I would create a 4th VDOM for the internet connection. This VDOM would have only the External Interface in it. I would then create virtual links between this " Internet" VDOM and my 3 " user" VDOMs. This setup gives you great flexibility and double NAT functionality and can also drastically reduce your rulebase. Jon
Still learning to type " the"
Still learning to type " the"
Not applicable

Setting up vlans on my provider side is not what i want to do, nor do i believe its worth the effort, as i can accomplish the same thing I need to do by placing some low end cisco routers infront of my fortigates. What i want to do is have my internet in one vdom and each of my different " customers" in separate vdoms, with a vlan interface associated with each vdom. I have figured out how to create the vdoms, and create vlan interfaces and associate them with the different vdoms. I am however confused about setting up the vlinks between the vdoms. I have tried create some vlinks between some vdoms. However i' m not exactly sure how to setup the routing, or policies to send traffic to this vdom (Such as how to setup a vip in this vdom etc...) What i would like to see in the fortigate vdom guides is something that shows how to actually set this up from start to finish. That doesn' t require seperate interfaces on the external side, all of there examples require that. Also what do you mean by double nat ?
doshbass
New Contributor III

Scott, Forget double NAt, I just meant that you can do great things to get around duplicate IP addresses etc. I am not sure where your difficulty lies. If you have created the VLINK then on each vdom that the vlink is between, you have a new interface. Routes and policies can be applied to these as if they were any other interface. What is confusing you is probably that the gui has no support for VLINK interfaces so you have to set them up in the CLI. STarngely enough once you have created them via CLI you can modify and edit them via the gui. This lack of support goes through to Policies and Routing as well, so create a minimal config for each of these in the CLI eg allow all from internal to vlink0. This will then show in the gui and you can do more with it. Jon
Still learning to type " the"
Still learning to type " the"
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors