Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
machiasiaweb
New Contributor

Management Interface Assignment best practice

Hello,

 

I have question when configuration Dedicated Management interface for my firewall.

 

Should I put it to root VDOM? or I should create another new VDOM and assign it there?  or another better practice?

 

Thanks!

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

It wouldn't be a matter if the purpose of the mgmt interface(s) is to get in the unit out-of-band with a super-user admin. We leave them in the default root vdom.

machiasiaweb

Then the others ports like WAN is better to split into another VDOM?  

 

One reason is if mgmt interface is using different path compare with WAN port to access Internet.

Another reason is better to manage.

Toshi_Esumi

Mgmt interfaces can't be used to carry user traffic. It wouldn't even show up in routing table. You probably saw (didn't see) in root vdom by now. It's dedicated to management purpose only. All the other ports can be used for any routings&firewallings, which you might want to move around vdoms depending on your network design with multiple vdoms.

FortiKoala

Here is a KB explaining best practice for the management interface http://kb.fortinet.com/kb/viewContent.do?externalId=FD37035

 

Labels
Top Kudoed Authors