12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Enabling VDOMs<br />

Using virtual domains<br />

Enabling VDOMs<br />

Using the default admin administration account, you can enable multiple VDOM<br />

operation on the <strong>FortiGate</strong> unit.<br />

To enable virtual domains<br />

1 Log in to the web-based manager as admin.<br />

2 Go to System > Status.<br />

3 In System Information, next to Virtual Domain select Enable.<br />

The <strong>FortiGate</strong> unit logs you off. You can now log in again as admin.<br />

When virtual domains are enabled, the web-based manager and the CLI are<br />

changed as follows:<br />

• Global and per-VDOM configurations are separated.<br />

• A new VDOM entry appears under System.<br />

• Only the admin account can view or configure global options.<br />

• The admin account can configure all VDOM configurations.<br />

• The admin account can connect through any interface in the root VDOM or<br />

though any interface that belongs to a VDOM for which a regular administrator<br />

account has been assigned.<br />

• A regular administrator account can configure only the VDOM to which it is<br />

assigned and can access the <strong>FortiGate</strong> unit only through an interface that<br />

belongs to that VDOM.<br />

When virtual domains are enabled, you can see what the current virtual domain is<br />

by looking at the bottom left of the screen. It will say Current VDOM: followed by<br />

the name of the virtual domain.<br />

Configuring VDOMs and global settings<br />

When Virtual Domains are enabled, only the default super admin account can:<br />

• configure global settings<br />

• create or delete VDOMs<br />

• configure multiple VDOMs<br />

• assign interfaces to a VDOM<br />

• assign an administrator to a VDOM<br />

A VDOM is not useful unless it contains at least two physical interfaces or virtual<br />

subinterfaces for in<strong>com</strong>ing and outgoing traffic. Only the super admin can assign<br />

interfaces or subinterfaces to VDOMs. A regular administrator account can create<br />

a VLAN subinterface on a physical interface within their own VDOM.<br />

Only the super admin can configure a VDOM unless you create and assign a<br />

regular administrator to that VDOM. Only the super admin can assign an<br />

administrator to a VDOM. An administrator account whose access profile provides<br />

read and write access to Admin Users can create additional administrators in its<br />

own VDOM.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

74 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!