12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring VDOMs and global settings<br />

Using virtual domains<br />

VLAN subinterfaces often need to be in a different VDOM than their physical<br />

interface. To do this, the super admin must first create the VDOM, then create the<br />

VLAN subinterface, and assign it to the required VDOM.<br />

System > Network > Interfaces is only in global settings, and is not available<br />

within any VDOM. For information on creating VLAN subinterfaces, see “Adding<br />

VLAN subinterfaces” on page 109.<br />

Assigning an interface to a VDOM<br />

The following procedure describes how to reassign an existing interface from one<br />

virtual domain to another. It assumes VDOMs are enabled and more than one<br />

VDOM exists.<br />

You cannot delete a VDOM if it is used in any configurations, such as having an<br />

interface in that VDOM. You cannot remove an interface from a VDOM if the<br />

interface is included in of any of the following configurations:<br />

• DHCP server<br />

• zone<br />

• routing<br />

• firewall policy<br />

• IP pool<br />

• proxy arp (only accessible through the CLI)<br />

Delete these items or modify them to remove the interface before proceeding.<br />

Note: An interface or subinterface is available for reassigning or removing once the delete<br />

icon is displayed. Until then, the interface is used in a configuration somewhere.<br />

To assign an interface to a VDOM<br />

1 Log in as admin.<br />

2 Go to System > Network > Interface.<br />

3 Select Edit for the interface that you want to reassign.<br />

4 Select the new Virtual Domain for the interface.<br />

5 Configure other settings as required and select OK. For more information on the<br />

other interfaces settings see “Interface settings” on page 83.<br />

The interface is assigned to the VDOM. Existing firewall IP pools and virtual IP<br />

addresses for this interface are deleted. You should manually delete any routes<br />

that include this interface, and create new routes for this interface in the new<br />

VDOM. Otherwise your network traffic will not be properly routed.<br />

Assigning an administrator to a VDOM<br />

If you are creating a VDOM to serve an organization that will be administering its<br />

own resources, you need to create an administrator account for that VDOM.<br />

A VDOM admin can change configuration settings within that VDOM but cannot<br />

make changes that affect other VDOMs on the <strong>FortiGate</strong> unit.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

76 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!