12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Virtual domains<br />

Using virtual domains<br />

By default, your <strong>FortiGate</strong> unit supports a maximum of 10 VDOMs in any<br />

<strong>com</strong>bination of NAT/Route and Transparent modes. For <strong>FortiGate</strong> models<br />

numbered 3000 and higher, you can purchase a license key to increase the<br />

maximum number of VDOMs to 25, 50, 100 or 250. For more information see<br />

“License” on page 199.<br />

Note: The <strong>FortiGate</strong>-224B in switch view does not support VDOMs.<br />

If virtual domain configuration is enabled and you log in as the default super<br />

admin, you can go to System > Status and look at Virtual Domain in the License<br />

Information section to see the maximum number of virtual domains supported on<br />

your <strong>FortiGate</strong> unit.<br />

By default, each <strong>FortiGate</strong> unit has a VDOM named root. This VDOM includes all<br />

of the <strong>FortiGate</strong> physical interfaces, VLAN subinterfaces, zones, firewall policies,<br />

routing settings, and VPN settings.<br />

Management systems such as SNMP, logging, alert email, FDN-based updates<br />

and NTP-based time setting use addresses and routing in the management<br />

VDOM to <strong>com</strong>municate with the network. They can connect only to network<br />

resources that <strong>com</strong>municate with the management virtual domain. The<br />

management VDOM is set to root by default, but can be changed. For more<br />

information see “Changing the Management VDOM” on page 77<br />

Once you add a VDOM you can configure it by adding VLAN subinterfaces,<br />

zones, firewall policies, routing settings, and VPN settings. You can also move<br />

physical interfaces from the root VDOM to other VDOMs and move VLAN<br />

subinterfaces from one VDOM to another. For more information on VLANs, see<br />

“VLAN overview” on page 107.<br />

For more information on VDOMs, see the <strong>FortiGate</strong> VLANs and VDOMs <strong>Guide</strong>.<br />

VDOM configuration settings<br />

The following configuration settings are exclusively part of a virtual domain and<br />

are not shared between virtual domains. A regular administrator for the VDOM<br />

sees only these settings. The default super admin can also access these settings,<br />

but must first select which VDOM to configure.<br />

• System settings<br />

• Zones<br />

• DHCP services<br />

• Operation mode (NAT/Route or Transparent)<br />

• Management IP (Transparent mode)<br />

• Router configuration<br />

• Firewall settings<br />

• Policies<br />

• Addresses<br />

• Service groups and custom services<br />

• Schedules<br />

• Virtual IPs<br />

• IP pools<br />

• Protection Profiles<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

72 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!