Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ascendmax
New Contributor

Do I need to extend my Vlans to FG to use vDoms?

I have four branch locations that tie into the data center where the FG is located. I need to create a vDom for each location/subnet. Do I need to stretch each Vlan to the FG and create a Vlan interface in the FG? Basically that would make the FG my default gateway for each subnet. I would like to make the downstream core switch my GW and just have a /30 link between the FG and the switch. Is this possible?

1 REPLY 1
blackhole_route
New Contributor III

In general it's best to use a tagged interface where it makes sense (taking into account bandwidth, external L2 domains, etc) , but that doesn't require stretching your downstream vlans up to the firewall. You could still have the downstream core switch serve as the gateway for each branch location and routed links between each fortigate vdom and the core switch.

 

That said, will the core switch provide route table separation between the four branch sites? If not, what's the purpose of a vdom per branch site and how would you route traffic to the appropriate vdom? And do the branch sites need to talk to each other? If so, intervdom links will quickly (i would think) become a pain point. It seems there are either some details  outside of what you've included which would clarify the scenario greatly, or there are some details that haven't been worked out which could prove to be obstacles to what you're trying to accomplish.

Labels
Top Kudoed Authors