Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
prince
New Contributor III

Vdom setup with ISP LAN pool

Dear support,

we need to setup vdom for current network setup and our configuration is to use the ISP-provided LAN IP pool (1.1.2.2/29 subnet) in vdom ,

Currently, our Fortinet firewall's WAN interface is configured with the WAN IP pool address (1.1.1.1/30), and it's functioning seamlessly. However, we now aim to utilize the ISP-provided LAN IP pool (1.1.2.2/29) for vdom internet connectivity using IP addresses within this subnet. we need to setup this for separate network. we need to use ISP provided one of the Lan pool iP address for WAN interface in VDOM. i need your support for this. can anyone share how to configure this.

14 REPLIES 14
Toshi_Esumi

And that's why you need to use vdom-link/npu-vlink to connect those client VDOMs to root vdom to route through. Then you can use the /31 subnet for both sides of vdom-link/npu-vlinks.

prince
New Contributor III

shall i assign this /29 ip address as lan laptop in firewall and connect this to cisco switch by creating separate vlan and connect the vlan to vdom interface as wan?

Toshi_Esumi

No. Each client VDOM is an independent router and the root VDOM is just a transit or a part of internet. You need to set NAT at the client VDOM and all LAN side would have private IPs. And the link between root VDOM and the client VDOM need to have the /31 public subnet.

Toshi

prince
New Contributor III

Hi Toshi,

I have configured ISP provided /29 IP address in the FortiGate interface as vlan4 and in cisco i have configured 3 vlan4 port .now in one vlan4 port i connected a laptop and check i can able internet from  /29 IP address. and i connected this vlan4  to port 8 to vdom interface as wan. and in port 6 i configured lan interface for this vdom. and i created policy from lan to wan and allowed all the service and enable nat in this. but after connecting to this vdom created lan internet is not working. i need your support.

 

Toshi_Esumi

This is how you could set up multiple VDOMs for clients. You never answered my question how many you need.

Toshi
vdoms.png

Labels
Top Kudoed Authors