Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor

Understanding Fortigate VDOM Concept

Dear All,

 

I have few quires with regard to VDOM concept which are as follows:-

 

1. In which cases do we use VDOM

2.  What are the benefits of VDOM in case If we use

3.   Does it provides similar concept like - Physical box.

4. Implement scenarios in the production environment. 

 

 

thank you.

 

3 REPLIES 3
ndumaj
Staff
Staff

Hello,

Virtual Domains (VDOMs) are used to divide a FortiGate into two or more virtual units that function independently. VDOMs can provide separate security policies and, in NAT mode, completely separate configurations for routing and VPN services for each connected network.

There are two VDOM modes:

  • Split-task VDOM mode: One VDOM is used only for management, and the other is used to manage traffic. See Split-task VDOM mode.
  • Multi VDOM mode: Multiple VDOMs can be created and managed as independent units. See Multi VDOM mode.

By default, most FortiGate units support 10 VDOMs, and many FortiGate models support purchasing a license key to increase the maximum number.

Global settings are configured outside of a VDOM. They effect the entire FortiGate, and include settings such as interfaces, firmware, DNS, some logging and sandboxing options, and others. Global settings should only be changed by top level administrators.

Please review the following articles:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/109991%20
https://docs.fortinet.com/document/fortiproxy/7.2.0/administration-guide/32293/configuration
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-multiple-VDOMs/ta-p/193601
https://community.fortinet.com/t5/FortiGate/Technical-Tip-System-and-performance-best-practice/ta-p/...

BR

- Happy to help, hit like and accept the solution -
AEK
SuperUser
SuperUser

Hi Umesh

When you need two or more firewalls, you can use VDOMs instead of buying extra firewall devices.

VDOMs separate quasi-physically the traffic, like if you have 2 or more firewalls.

It provides same capabilities as firewall.

Examples:

  • Many companies adopt architecture with frontal firewall and dorsal firewall, in that case you can use VDOMs instead ot 2 physical firewalls
  • Other companies have strict security standards in which they require separating some network traffic from others. Even if we can do that without VDOMs but their standards requires something like VRFs or VDOMs
  • Some ISP sell firewall as service, they have a big FG 3000F with extra VDOM license in order to have hundreds of VDOMs on their device, so they can sell virtual firewalls to their customers
AEK
AEK
Toshi_Esumi
SuperUser
SuperUser

A few supplemental comments to those two posts above.
- Split-task VDOM was discontinued with 7.2 because not much specific benefits. Now only options under "config system global" are:

set vdom-mode [no-vdom|multi-vdom]

- The num of VDOMs more than 10 are available FG1000x or above with VDOM licenses.
- We're a MSP hosting multiple customers on one box. In that case, one VDOM per customer is a must to separate customers.

Toshi

Labels
Top Kudoed Authors