Hi all, with the latest FortiOS I have setup VDOMs on my network including inter-vdom routing, but am finding myself running out of IP addresses.
So far I have setup WAN1 with our uplink, 193.200.200.2/30, and static route to 193.200.200.1.
I have a block of IPs (91.100.100.0/27) routed to me over the above uplink connection.
I then create a VDOM link from root to my “prod” vdom, the with the root side (prod0 = 91.100.100.1) and vdom side (prod1 = 91.100.100.2).
I then set the rules on root to allow traffic to/from the prod vdom, and within the prod vdom set a static route to 91.100.100.1.
I do the same for qa vdom, using root side (qa0 = 91.100.100.5) and qa side (qa1 = 91.100.100.6), setup rules and route etc.
It works, but I am burning up IPs very quickly, I tried using no ips (0.0.0.0/0.0.0.0) on inter-vdom links and default route with no IP, but doesn’t work so I am screwing something up.
Is there a more efficient way of performing this routing that can reduce IPs and ideally allow me to assign any single /32 IP per vdom?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.