Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
prince
New Contributor III

Vdom setup with ISP LAN pool

Dear support,

we need to setup vdom for current network setup and our configuration is to use the ISP-provided LAN IP pool (1.1.2.2/29 subnet) in vdom ,

Currently, our Fortinet firewall's WAN interface is configured with the WAN IP pool address (1.1.1.1/30), and it's functioning seamlessly. However, we now aim to utilize the ISP-provided LAN IP pool (1.1.2.2/29) for vdom internet connectivity using IP addresses within this subnet. we need to setup this for separate network. we need to use ISP provided one of the Lan pool iP address for WAN interface in VDOM. i need your support for this. can anyone share how to configure this.

14 REPLIES 14
jiahoong112
Staff
Staff

please upload a diagram on what you intend on doing. if i am understanding your query correctly, you already have a vdom with internet connectivity. And now you want to make another internet breakout on another vdom?

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
prince
New Contributor III

Hi,

My ISP( tata Lease line) has Provided two wan subnet they are /30( 1.1.1.1/30) and /29 (1.1.2.2/29)subnet both are in different subnet ip address. for ISP they mentioned /30 ip address as WAN ip pool and /29 ip address as lan IP pool. I connected /30 ip address from Tata MUX interface to FortiGate firewall wan interface. And its working fine. now I need to create separate network for my client. so I enabled VDOM in FortiGate setting. and I named the VDOM as sales. And I assigned one of the FortiGate port, say port 10 for VDOM. for this VDOM, I need to use the ISP provided /29 ip address i.e. 1.1.2.2/29. I need to assign one of the ip address from this /29 with this VDOM interface and assign as WAN. I need to know whether I can assign this IP address to the created vdom WAN interface and will it work? i need your support for this.

hbac
Staff
Staff

Hi @prince,

 

I believe you want each VDOM to have its own wan interface. You can assign a physical interface to that VDOM and configure IP address and default route. You can refer to https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/317358/inter-vdom-routing-co...

 

Regards, 

prince
New Contributor III

my problem is isp provided two different subnet ip address ie /30 and /29 ip ranges. i connected /30 ip address with isp mux to Fortinet wan interface. and i need use utilize this one of the /29 ip address for vdom wan interface. but cant able to configure /29 ip address to vlan physical port. for this i need to support.

prince
New Contributor III

Hi 

I have configured ISP provided /29 IP address in the FortiGate interface as vlan4 and in cisco i have configured 3 vlan4 port .now in one vlan4 port i connected a laptop and check i can able internet from  /29 IP address. and i connected this vlan4  to port 8 to vdom interface as wan. and in port 6 i configured lan interface for this vdom. and i created policy from lan to wan and allowed all the service and enable nat in this. but after connecting to this vdom created lan internet is not working. i need your support.

 

Toshi_Esumi
SuperUser
SuperUser

How many VDOMs do you need? You need to split the /29 into multiple smaller subnets and assign each to the vdom-link/npu-vlink for each VDOM. The smallest you can make is /31. So with /29, you can accommodate only 4 VDOMs. That's why I asked how many you need. If you need more than 4, you need to get either more subnets or a bigger subnet from the ISP.

Toshi

prince
New Contributor III

i need to create one vdom for client 

Toshi_Esumi

how many clients?

Toshi_Esumi

And you can not have a different physical wan interface for the client VDOM to connect to the same ISP. That /29 is assigned by the ISP and the ISP expects that the subnet is BEHIND the /30 sbnet. You have to route through the wan interface that you must have configured in root vdom.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors