FortiOS VDOMs - What are they and why do we need them?

Поделиться
HTML-код
  • Опубликовано: 15 сен 2018
  • An overview of Virtual Domains (VDOMs) and where they will be applicable to you.
    VDOMs are incredibly powerful and they give you the opportunity to maximize the utilization of your FortiGate. www.fortinetguru.com
    Buy Hardware: bit.ly/2QZVeqh
    Get Consulting: bit.ly/36FinSU
    My Other Projects:
    Office Of The CISO: bit.ly/3HGMH1o
    Packet Llama: bit.ly/3SEX3H4
    ###### SOCIAL LINKS ######
    Twitter: bit.ly/2WXiRAv
    Facebook: bit.ly/3eigz4D
    Instagram: bit.ly/3cZneAz
    ######################

Комментарии • 45

  • @JeremiahBurns
    @JeremiahBurns 5 лет назад +1

    Brilliant summary. Thanks for this.

  • @LVang152
    @LVang152 3 месяца назад

    I start to like how fortinet manage the firewall.

  • @techno_ocean1938
    @techno_ocean1938 5 лет назад +4

    U are one of the best for fortunate trainer,
    Can you make video on hardening configuration of fortigate firewall using CLI?

  • @rolandnowak1131
    @rolandnowak1131 Год назад

    Thanks!

  • @saudnaeem
    @saudnaeem 4 года назад

    good info. mate

  • @jeyav
    @jeyav 2 года назад

    Hi Mike, one doubt in our lab we have 6 different environments for eg., dev, uat, staging etc but tricky part is we need to communicate between these environments dev middleware or portal VMs need to talk with staging VMs, will this VDOM concept helps us in this scenario? we want complete segregation + communication between them, right now we are managing by assigning various vlans for each environment.

  • @wahibaelamine8927
    @wahibaelamine8927 5 лет назад +2

    thank you for your efforts
    my question is about interfaces, i know that he models supprt over 500 vdoms, so how can we manage interfaces (if a vdm needs at least 2 interfaces one for wan and one for lan) , they are gonna be virtual ?

    • @sameerpervaiz3142
      @sameerpervaiz3142 4 года назад +1

      when you create multiple VDOM you allocate-interface at global level. Yes, you can allocate. There is not any limit for the interface for VDOM.

  • @Mrvivi18
    @Mrvivi18 Год назад

    Thanks Mike.. This video is still useful in 2022 .. One question what is the relationship or difference between VDOM and ADOM ..

    • @wzhaicthtaarkyer
      @wzhaicthtaarkyer Год назад

      Adom "administrative domain" is on fortimanager. vdom "virtual domain" is on the gate

  • @daveking1117
    @daveking1117 3 года назад +1

    Does it make sense to use VDOMs in an HA cluster for load balancing roles/tasks in a single organization therefore making use of the processing power of each node?

    • @FortinetGuru
      @FortinetGuru  3 года назад

      I don’t. I normally use VDOMs for segmentation of the device into different service needs. For instance, having multiple clients that all want to manager their stuff on your firewall, you give them a VDOM. Want to have a beefy firewall serve as a perimeter firewall but also VPN termination point but you want the services separated somehow, VDOM….things like that

    • @jg97911
      @jg97911 3 месяца назад

      @@FortinetGuru We were looking into getting a couple 90G's in HA for front end perimeter (to serve the WAN/VPN and DMZ) and a couple 900G's HA for the core to segregate internal vlans and communication. I proposed another idea of just getting 2x 900G's with VDom's to do this instead of purchasing 2 sets of firewalls. what are your thoughts?

  • @khaledmadani8675
    @khaledmadani8675 2 года назад

    Hii
    from forticlient how i can access branches with fortigate hub and spoke vpn network?

  • @garyredmond1890
    @garyredmond1890 4 года назад +1

    Hi Mike, new subscriber here. Loving the Fortigate content, really helping with a work deployment and my Fortigate knowledge in general. I'm in a situation where I need to replace a pair of Linux Shorewall firewalls with a pair of Fortigate 300Ds in HA; you mentioned in this video about utilizing VDOMs in firewall migration scenarios, which sounds like it could be a huge help in my project, do you know of any documentation or articles that go into more detail around using VDOMs for migrations?

    • @FortinetGuru
      @FortinetGuru  4 года назад

      I have a whiteboard session video that describes the logical and physical design of that deployment.

    • @garyredmond1890
      @garyredmond1890 4 года назад

      @@FortinetGuru Ah, Replacing Old ASA, Didn't spot that, will take a look now. Thank you for responding.

    • @sameerpervaiz3142
      @sameerpervaiz3142 4 года назад

      Make sure you configure the one device and then build the HA. Extract as much configuration info as you can from old devices.

    • @garyredmond1890
      @garyredmond1890 4 года назад

      @@sameerpervaiz3142 I didn't ask about HA, and extracting as much config from the legacy devices is an obvious part of the process.

    • @drostoker
      @drostoker 4 года назад +1

      @@FortinetGuru I really would like to see a video of you using VDOMs to the migration. This sounds like an excellent way to do this. Thanks for all you work.

  • @RJ-uf3cr
    @RJ-uf3cr 3 года назад +1

    my firewall has 20 vdoms, and i need to check route( who's L3 gw is one of the vdom out of 20) that is in which vdom the route belongs to, so is there any global routing table in root or how can i get to know where the route belongs to which vdom. Thank you in advance for your answer

    • @FortinetGuru
      @FortinetGuru  3 года назад

      The VDOMs are logical separations. As far as everything else is concerned they are separate boxes.

    • @zechzou385
      @zechzou385 3 года назад

      Hi Mike, great video! I actually have similar question. When I get a request to do the firewall policy, how could I tell the specific source address belongs to which vdom’s route? Thanks.

  • @thearlh
    @thearlh 5 лет назад

    how does the interfaces fit into the Vdoms ? If i understand correctly an interface can be in only one VDOM , right ?
    port1 and port2 belong to Vdom A ; port 2 and port3 to VDOM B . similar to WAn1 and PORT 4 to VDOM C ..etc can you clarify a bit ? thx

    • @FortinetGuru
      @FortinetGuru  5 лет назад

      an interface can only belong to a single VDOM. So if you have 1 and 2 assigned to VDOM A then those ports are unavailable to any other VDOMs

    • @sameerpervaiz3142
      @sameerpervaiz3142 4 года назад +1

      it totally depends on your topology, if you want to allocate physical interfaces to the VDOM you can allocate them. My approach is to create the port group on the firewall and then use trunking and allocate each logical interface to the VDOM.

    • @jessehayford1991
      @jessehayford1991 3 года назад

      VDOMS come with a single management VDOM. Make sure all your phisical interfaces belong to that management VDOM - default i root and can be changed. Then create sub-interfaces on those physical interfaces. Those sub-interfaces can be given to any VDOM in the configuration.

  • @sameerpervaiz3142
    @sameerpervaiz3142 4 года назад +1

    I have seen lots of engineers create inter VDOM link with root VDOM for Customer VDOM's which is not a recommended way. The best way is to use dot1q tagging and allocate that tagged interface to the customer VDOM

    • @FortinetGuru
      @FortinetGuru  4 года назад

      There are many ways to skin this cat and they are almost all up to the user and their preference. I use VDOM links quite often without issue.

  • @LucPaulin
    @LucPaulin 5 лет назад +2

    So if I understand correctly, we can consider vdom kind of VRF

    • @FortinetGuru
      @FortinetGuru  5 лет назад +1

      I wouldn't say VRF directly. IT has some of the same benefits (single device with multiple routing tables) But this is almost like taking a physical device and physically breaking it into multiple smaller ones to provide segmentation between clients while also providing clients the ability to administer their policies without having access to items that don't belong to them.

    • @masajjad
      @masajjad 4 года назад +1

      Something like Virutal Context in Cisco ASA

    • @victors8809
      @victors8809 3 года назад +1

      I think that the best comparison for VDOMs is with Virtual Contexts in Cisco ASA :)

  • @noobsniperxx
    @noobsniperxx 3 года назад +1

    So multi context mode for ASA just for fortigates.....Can you create the vdom in Fortimanager

    • @FortinetGuru
      @FortinetGuru  3 года назад

      Yeah.

    • @noobsniperxx
      @noobsniperxx 3 года назад

      @@FortinetGuru have you notice any bugs with Fortimanager with importing Firewalls that already have configs in it. I noticed in my lab that every time I import a already setup HA pair my policies stop working. I’m using 6.4.4 with a trial license I my lab. I’m also using FortiAnalyzer 6.4.4 (trial) and I can’t get my fortigates to communicate with it even though I can’t ping it.

  • @zmsaw
    @zmsaw Год назад

    Do I need to keep an interface or port in root vdom (say mgmt vdom) for ntp, dns etc?

    • @FortinetGuru
      @FortinetGuru  Год назад

      You need a port in whatever vdom is configured for managing the device. (Management role assignment, not management interfaces). That’s the interface that the gate will use for fortiguard and other lookups.

  • @lovedefeatsus
    @lovedefeatsus 2 года назад

    can you use VRFs without multiple VDOMs?

  • @moorefa
    @moorefa 4 года назад

    God forbid one of those Meraki's.... Hysterical, because it is true!

    • @FortinetGuru
      @FortinetGuru  4 года назад

      The Merakis are growing on me. As long as you are using Meraki all the way through the stack though.

    • @EverythingEvo
      @EverythingEvo 3 года назад +2

      @@FortinetGuru I've managed Meraki's for 6 years. Yeah the GUI is easy to use but man am I glad to be moving my company over to FortiGates. Meraki is not a true next gen firewall IMO. No SSL/TLS decryption, no IPv6 support, No built in VPN client, the logging is a joke, no vmware virtual appliance, and to top it off, if you stop paying the license they turn into bricks and nothing on the device will function, not even basic routing. It's crazy how much more you have to pay for Meraki and their insanely extensive licensing in comparison to FortiGate too but you get so so so much less.

  • @Traumatree
    @Traumatree 2 года назад

    BUT, if you are using fortilinks, it is a pain in the b*tt and vlan and port config of the FortiSwitch has all to be managed via CLI only, which defeat the purpose of using the Fortinet ecosystem to some degree. If your Fortigate is not using fortilink, using the firewalls interface is ok.