Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jshdcooper
New Contributor

EMAC Routing Between Vdoms

Hi All,

 

Anyone have experience with EMACs? We have a campus where we broke student traffic to one vdom, and faculty traffic to the other. We want to treat all student traffic as if it was internet only and apply security profiles as it PATs.

Obviously, there are some servres hosted internally on the faculty vdom they need access to. We expected it to route out, ask who has that public IP, since it's on that same network, and then route into the faculty vdom. Unfortunately, that doesn't seem to work. Packet captures show it's broadcasting for that IP, but getting no response. It also seems that I can't set a static ARP entry on the WAN interfaces.

Just wondering if anyone else has run into an issue like this.

 

Thanks!

1 REPLY 1
lobstercreed
Valued Contributor

We're doing this without the separate VDOMs.  We needed to set up rules between the faculty network and the student network to allow the students to access what they needed (using the VIPs) and drop all other traffic.  I imagine you're running up against something similar but the solution maybe isn't as simple since you're using VDOMs.  I'll let somebody with more knowledge of VDOMs weigh in... 

 

I am curious though why you chose to use VDOMs?  As I understand it, this is mainly to allow different routing contexts and/or different staff to manage different interfaces.  In our shop it is 3 of us managing everything anyway, so VDOMs seemed pointless.

Labels
Top Kudoed Authors