Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FatalHalt
Contributor II

ADOM 'VPN Management' Modes

Hey guys, 

 

I'm trying to figure out what the differences are between 'Central VPN Console' and 'Policy & Device VPNs' when making a new ADOM. I've read through the Admin guide, and it talks a bit about the Central mode, but I'm still a bit lost as to what its goal is and what makes it different from the other option. 

 

Could anyone elaborate a bit for me?

 

Cheers!

6 REPLIES 6
AndreaSoliva
Contributor III

Hi

 

if you are using ADOM with Central VPN Console it is a way to configure all existing FGT in this ADOM in a fast way for a fully meshed or star topology without configuring every device with a IPSec. This means the VPN console is something like a template which you define the phase-1/2. After that you insert the FGT in this template and this is the reason they receive the config of phase-1/2 of the template. Within the template you define the FGT as hub and/or spoke as the lan subnet etc. You can choose also if routing should be done automatically or not. There are some restrictions specially if you are not working with fix IP specially related to Dial-Up. There are also some other stuff to know if you work with Central VPN Console.

 

If you use not Central Console you use the IPSec config like on common behaviour meaning configuring each device with IPSec and routing policy etc. etc.

 

Specially if you are rolling out a lot of device's within a Central VPN Console you should really test and look deeper into the case to be prepared and know what happens if you roll out.

 

This is more or less a short overview and description about Central VPN Console...

 

hope this helps

 

have fun

 

Andrea

FatalHalt

Interesting! I like that. 

 

So, if I have an ADOM with 4 geographically diverse firewalls that I would like to have fully meshed, this is a quick way to accomplish that? I'll have to play around with it. 

 

Does this have any affect on configuring other IPsec tunnels from one of the particular firewalls in the ADMON? Would I still be able to do that on demand?

AndreaSoliva
Contributor III

Hi

 

So, if I have an ADOM with 4 geographically diverse firewalls that I would like to have fully meshed, this is a quick way to accomplish that? --> Absolutly yes and is the goal of Central VPN Console specially about the routing because if you want it will be done fully automatically! You can imagine if you have let's say 10 Devices fully meshed and every device has 3 subnet how many routing entries you have to do on each device....horrible!    Does this have any affect on configuring other IPsec tunnels from one of the particular firewalls in the ADMON? Would I still be able to do that on demand? --> If you mean if you can configure addtional IPSec with none FGT's or none FGT device's? If yes the answer is yes which means: Within a Central Console you can choose the FGT within the ADOM or "external manage gateways" which means FGT Devices not within the ADOM with the Centra Console . Also none FGT devices are possible within the Central Console. I had never situations which I used mixed mode meaning Central Consoel and the tradional mode.

 

To use Central Console has some advantage but be careful and test the stuff specially if you have 3rd party devices etc.

 

hope this helps

 

have fun

 

Andrea

boneyard

i had some experience with this recently which i would like to share.

 

turning on the central VPN console directly disables your earlier access to VPNs via the device management tab. turning it off enables this again. your current VPNs remain working, but accessing them via fortimanager isn't possible.

 

so if you consider central VPN console do it from the start, enabling it later on which require a migration if you want to remain in full control.

 

using it is nice for the things it seems meant for, managing large mesh or star topologies. in my opinion they should have accommodated your more general site-2-site VPNs a bit better. also the fact you get three extra interfaces per topology of which two (or one) you wont use is kinda silly. still for managing that mesh it is awesome.

catalinv

Hi,

could you please help me understand what happens in the following situation:

I have VPN centralized management enabled and 4 communities configured for about 16 devices.

If I disconnect the fortigates from the fortimanager, can I reconnect them later and use the same configuration in the same ADOM, or move to another VDOM?

 

Thank you,

Catalin

chall_FTNT

> If I disconnect the fortigates from the fortimanager, can I reconnect them later and use the same configuration in the same ADOM,

 

As long as you do not delete the device from FortiManager, reconnecting later should not result in the VPN configuration being removed.

 

> or move to another ADOM?

 

If added to a new ADOM, the VPN configuration previously added by VPN manager would be deleted.

Chris Hall
Fortinet Technical Support
Labels
Top Kudoed Authors