FortiGate VDOMs: Partitioning, Routing and Management - 夜莺博客

FortiGate VDOMs: Partitioning, Routing and Management

One FortiGate, several logically independent firewalls: that is what virtual domains deliver. VDOMs are the standard way to serve multiple tenants, separate production from lab, or give a managed-services team its own policy space on shared hardware. They are also the setting people enable casually and then discover their interfaces, routing and administrators are all suddenly scoped. This guide covers the mechanics, the inter-VDOM link, and how VDOMs interact with HA before you commit.

Enabling VDOM mode

config system global
    set vdom-mode multi-vdom
end

Switching to multi-VDOM reboots the unit on many firmware trains and moves all existing configuration into the root VDOM. Take a configuration backup first. Afterwards every interface, static route, policy and admin account belongs to exactly one VDOM, and you change context with config vdom / edit <name> in the CLI, or the VDOM selector in the GUI.

Creating a VDOM and giving it interfaces

config vdom
    edit customerA
end

config global
    config system interface
        edit "port10"
            set vdom "customerA"
            set mode static
            set ip 192.168.100.1 255.255.255.0
            set allowaccess ping https ssh
        next
    end
end

An interface belongs to one VDOM only, and a VDOM cannot see another VDOM's routing table. That isolation is the point - but it also means any inter-VDOM traffic must be routed deliberately.

Routing between VDOMs: inter-VDOM links

config global
    config system vdom-link
        edit "vl-custA-mgmt"
        next
    end
    config system interface
        edit "vl-custA-mgmt0"
            set vdom "customerA"
            set ip 10.255.0.1 255.255.255.252
        next
        edit "vl-custA-mgmt1"
            set vdom "mgmt"
            set ip 10.255.0.2 255.255.255.252
        next
    end
end

The pair of interfaces behaves like a two-port cable between the VDOMs. You still need policies in both directions, and static routes or a dynamic protocol to move prefixes across. For shared internet access, either give each VDOM its own WAN interface or route through a transit VDOM - do not assume VDOMs can share a NAT rule.

Administration scope

config system admin
    edit "tenantA-admin"
        set vdom "customerA"
        set accprofile "tenant-readwrite"
    next
end

A restricted admin with a VDOM-scoped profile can manage only their own domain: no visibility into other VDOMs, no global settings. This scoping is usually the business justification for the whole design, so test it explicitly - a profile that is too broad is a silent privilege escalation.

VDOMs and high availability

  • In an HA cluster, VDOMs exist on both members and must be kept identical in name and interface mapping.
  • Virtual clustering (VDOM partitioning) lets you designate which VDOM is primary on which member, so tenant A can be active on unit 1 while tenant B is active on unit 2 - useful for splitting load rather than having one node idle.
  • Some settings live in the global VDOM and cannot be partitioned; plan which VDOM carries management and which hosts the HA management interface before failing over.
  • Sessions and VDOM state follow the HA sync rules, so verify failover per VDOM, not just once for the device.

Verification and housekeeping

show vdom list                       # all VDOMs, mode and status
diagnose sys vd list | grep -A2 customerA
get system status | grep VDOM
diagnose sys session stat | grep -i vdom

Watch resource consumption per VDOM in the dashboard - a single VDOM with an idle session timeout of 3600 or a runaway session table can consume memory global to the device. Keep the number of VDOMs small and purposeful; every additional one adds interfaces, routes and policy pairs that must all be audited. If remote access is the driver for the design, the same platform partitioning logic applies to the SSL VPN side, covered in FortiGate SSL VPN Web Mode: Configuration Guide.

Related reading on this site: FortiGate HA Failover Troubleshooting (FGCP) and FortiGate FortiOS CLI Troubleshooting: Cheat Sheet.

原文链接:https://community.fortinet.com/fortigate-3/technical-tip-best-practices-when-using-the-virtual-cluster-vdom-partitioning-feature-229593