{"id":282,"date":"2022-04-09T22:27:45","date_gmt":"2022-04-10T02:27:45","guid":{"rendered":"https:\/\/opentextbc.ca\/fortigatefirewall\/chapter\/inter-vdom-routing\/"},"modified":"2023-08-29T16:27:29","modified_gmt":"2023-08-29T20:27:29","slug":"inter-vdom-routing","status":"publish","type":"chapter","link":"https:\/\/opentextbc.ca\/fortigatefirewall\/chapter\/inter-vdom-routing\/","title":{"raw":"8.2 Inter-VDOM Routing","rendered":"8.2 Inter-VDOM Routing"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n \t<li>Configure a VDOM to pass traffic between VDOMs<\/li>\n \t<li>Configure an Inter-VDOM routing<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox shaded\"><strong>Scenario<\/strong>: Inter-VDOM routing is the communication between VDOMs. VDOM links are virtual interfaces that connect VDOMs. A VDOM link contains a pair of interfaces, each one connected to a VDOM and forming either end of the inter-VDOM connection. We want to create a link between VDOM Sales and Accounting, then the traffic from WebTerm1 should be reached to WebTerm2.<\/div>\n\n[caption id=\"attachment_266\" align=\"alignnone\" width=\"906\"]<img class=\"wp-image-266 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2022\/03\/71.jpg\" alt=\"Inter-VDOM routing main scenario\" width=\"906\" height=\"393\"> Figure 8.19: Main scenario[\/caption]\n<table class=\"aligncenter\" style=\"width: 100%;\"><caption>Table 8.2: Devices configuration<\/caption>\n<tbody>\n<tr style=\"height: 18px;\">\n<th style=\"width: 137.375px; height: 18px;\" scope=\"col\">Device<\/th>\n<th style=\"width: 330.864px; height: 18px;\" scope=\"col\">IP address<\/th>\n<th style=\"width: 149.42px; height: 18px;\" scope=\"col\">Access<\/th>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 137.375px; height: 18px;\">WebTerm1<\/td>\n<td style=\"width: 330.864px; height: 18px;\">192.168.1.2\/24<\/td>\n<td style=\"width: 149.42px; height: 18px;\">-<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 137.375px; height: 18px;\">WebTerm2<\/td>\n<td style=\"width: 330.864px; height: 18px;\">172.16.1.2\/24<\/td>\n<td style=\"width: 149.42px; height: 18px;\">-<\/td>\n<\/tr>\n<tr style=\"height: 141px;\">\n<td style=\"width: 137.375px; height: 141px;\">FortiGate<\/td>\n<td style=\"width: 330.864px; height: 141px;\">Port 1: DHCP Client\n\nPort 2: 172.16.1.1\/24\n\nPort 3: 192.168.1.1\/24<\/td>\n<td style=\"width: 149.42px; height: 141px;\">Port 1: https, ping<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 137.375px; height: 18px;\">Cloud1<\/td>\n<td style=\"width: 330.864px; height: 18px;\"><\/td>\n<td style=\"width: 149.42px; height: 18px;\">-<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ol>\n \t<li>First, enable VDOMs in the firewall.\n<div class=\"textbox shaded\">\n\n<em>FGVM01TM19008000 # config system global<\/em>\n\n<em>FGVM01TM19008000 (global) # set vdom-mode multi-vdom<\/em>\n\n<em>FGVM01TM19008000 (global) # end<\/em>\n\n<\/div><\/li>\n \t<li>Create two VDOMs, <strong>Sales<\/strong> and <strong>Accounting.<\/strong>\n\n[caption id=\"attachment_268\" align=\"aligncenter\" width=\"450\"]<img class=\"wp-image-267\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/72.jpg\" alt=\"Create a VDOM sales\" width=\"450\" height=\"130\"> Figure 8.20: Create a VDOM Sales[\/caption]\n\n[caption id=\"attachment_268\" align=\"aligncenter\" width=\"450\"]<img class=\"wp-image-268\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/73.jpg\" alt=\"Create a VDOM Accounting\" width=\"450\" height=\"143\"> Figure 8.21: Create a VDOM Accounting[\/caption]<\/li>\n \t<li>Configure IP addresses for the Interfaces Port2 and Port3. Assign port3 to Sales Vdom and port2 to Accounting Vdom.\n\n[caption id=\"attachment_271\" align=\"alignnone\" width=\"1145\"]<img class=\"wp-image-269 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/74.jpg\" alt=\"port2 and port3 IP Address configuration\" width=\"1145\" height=\"186\"> Figure 8.22: Port2 and Port3 IP address configuration[\/caption]\n\n[caption id=\"attachment_271\" align=\"alignnone\" width=\"1129\"]<img class=\"wp-image-270 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/75.jpg\" alt=\"Port2 Configuration\" width=\"1129\" height=\"477\"> Figure 8.23: Port2 configuration[\/caption]\n\n[caption id=\"attachment_271\" align=\"alignnone\" width=\"1185\"]<img class=\"wp-image-271 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/76.jpg\" alt=\"Port3 Configuration\" width=\"1185\" height=\"434\"> Figure 8.24: Port3 configuration[\/caption]<\/li>\n \t<li>Go to <strong>Global VDOM<\/strong> &gt; <strong>Network Interfaces<\/strong> &gt; <strong>Create a new VDOM<\/strong> Link, and configure it as Figure 8.25:\n\n[caption id=\"attachment_272\" align=\"aligncenter\" width=\"1192\"]<img class=\"wp-image-272 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/77.jpg\" alt=\"Create a VDOM link between Sales and Accounting\" width=\"1192\" height=\"777\"> Figure 8.25: Create a VDOM link between Sales and Accounting[\/caption]<\/li>\n \t<li>In Accounting VDOM, Create two static routes:\n<ul>\n \t<li><strong>Destination: <\/strong>192.168.1.0\/255.255.255.0<\/li>\n \t<li><strong>Interface:<\/strong> Accounting-Sales<\/li>\n \t<li><strong>Gateway:<\/strong> 10.10.10.2<\/li>\n<\/ul>\n[caption id=\"attachment_274\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-273\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/78.jpg\" alt=\"Create a static route in Accounting VDOM\" width=\"400\" height=\"219\"> Figure 8.26: Create a static route in Accounting VDOM[\/caption]\n<ul>\n \t<li><strong>Destination: <\/strong>172.16.1.0\/255.255.255.0<\/li>\n \t<li><strong>Interface:<\/strong> Accounting-Sales<\/li>\n \t<li><strong>Gateway:<\/strong> 10.10.10.2<\/li>\n<\/ul>\n[caption id=\"attachment_274\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-274\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/79.jpg\" alt=\"Create a static route in Accounting VDOM\" width=\"400\" height=\"187\"> Figure 8.27: Create a static route in Accounting VDOM[\/caption]<\/li>\n \t<li>In Accounting VDOM, Create two Firewall Policies:\n<ul>\n \t<li><strong>Incoming:<\/strong> Port 2<\/li>\n \t<li><strong>Outgoing:<\/strong> AS0<\/li>\n \t<li>NAT Disable<\/li>\n<\/ul>\n[caption id=\"attachment_276\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-275\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/81.jpg\" alt=\"Create a Firewall Policy in Accounting VDOM from Port2 to AS0\" width=\"400\" height=\"331\"> Figure 8.28: Create a Firewall Policy in Accounting VDOM from Port2 to AS0[\/caption]\n\nIncoming:\n<ul>\n \t<li><strong>Incoming:<\/strong> AS0<\/li>\n \t<li><strong>Outgoing<\/strong>: Port2<\/li>\n \t<li>NAT Disable<\/li>\n<\/ul>\n[caption id=\"attachment_276\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-276\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/80.jpg\" alt=\"Create a Firewall Policy in Accounting VDOM from AS0 to Port2\" width=\"400\" height=\"354\"> Figure 8.29: Create a Firewall Policy in Accounting VDOM from AS0 to Port2[\/caption]<\/li>\n \t<li>In Sales VDOM, Create two static routes:\n<ul>\n \t<li><strong>Destination:<\/strong> 192.168.1.0\/255.255.255.0<\/li>\n \t<li><strong>Interface:<\/strong> AS1<\/li>\n \t<li><strong>Gateway:<\/strong> 10.10.10.1<\/li>\n<\/ul>\n[caption id=\"attachment_278\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-277\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/82.jpg\" alt=\"Create a static route in sales VDOM\" width=\"400\" height=\"227\"> Figure 8.30: Create a static route in Sales VDOM[\/caption]\n<ul>\n \t<li><strong>Destination:<\/strong> 172.16.1.0\/255.255.255.0<\/li>\n \t<li><strong>Interface:<\/strong> AS1<\/li>\n \t<li><strong>Gateway:<\/strong> 10.10.10.1<\/li>\n<\/ul>\n[caption id=\"attachment_278\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-278\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/83.jpg\" alt=\"Create a static route in sales VDOM\" width=\"400\" height=\"229\"> Figure 8.31: Create a static route in Sales VDOM[\/caption]<\/li>\n \t<li>In Sales VDOM, Create two Firewall Policies:\n<ul>\n \t<li><strong>Incoming:<\/strong> Port3<\/li>\n \t<li><strong>Outgoing:<\/strong> AS1<\/li>\n \t<li><strong>NAT Disable<\/strong><\/li>\n<\/ul>\n[caption id=\"attachment_280\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-279\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/84.jpg\" alt=\"Create a Firewall Policy in sales VDOM from Port3 to AS1\" width=\"400\" height=\"415\"> Figure 8.32: Create a Firewall Policy in Sales VDOM from Port3 to AS1[\/caption]\n<ul>\n \t<li><strong>Incoming:<\/strong> AS1<\/li>\n \t<li><strong>Outgoing:<\/strong> Port3<\/li>\n \t<li>NAT Disable<\/li>\n<\/ul>\n[caption id=\"attachment_280\" align=\"aligncenter\" width=\"400\"]<img class=\"wp-image-280\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/85.jpg\" alt=\"Create a Firewall Policy in sales VDOM from AS1 to Port3\" width=\"400\" height=\"393\"> Figure 8.33: Create a Firewall Policy in Sales VDOM from AS1 to Port3[\/caption]<\/li>\n \t<li>Now, you should verify your configuration and should be able to ping from WebTerm1 to WebTerm2.\n\n[caption id=\"attachment_281\" align=\"aligncenter\" width=\"711\"]<img class=\"wp-image-281 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/86.jpg\" alt=\"you should verify your configuration and should be able to ping from WebTerm1 to WebTerm2\" width=\"711\" height=\"508\"> Figure 8.34: Verify configuration[\/caption]\n\nTo delete a VDOM link in the CLI:\n<div class=\"textbox shaded\">\n\n<em>config system vdom-link<\/em>\n\n<em>delete &lt;VDOM-LINK-Name&gt;<\/em>\n\n<em>end<\/em>\n\n<\/div><\/li>\n<\/ol>","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Configure a VDOM to pass traffic between VDOMs<\/li>\n<li>Configure an Inter-VDOM routing<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox shaded\"><strong>Scenario<\/strong>: Inter-VDOM routing is the communication between VDOMs. VDOM links are virtual interfaces that connect VDOMs. A VDOM link contains a pair of interfaces, each one connected to a VDOM and forming either end of the inter-VDOM connection. We want to create a link between VDOM Sales and Accounting, then the traffic from WebTerm1 should be reached to WebTerm2.<\/div>\n<figure id=\"attachment_266\" aria-describedby=\"caption-attachment-266\" style=\"width: 906px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-266 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2022\/03\/71.jpg\" alt=\"Inter-VDOM routing main scenario\" width=\"906\" height=\"393\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2022\/03\/71.jpg 906w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2022\/03\/71-300x130.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2022\/03\/71-768x333.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2022\/03\/71-65x28.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2022\/03\/71-225x98.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2022\/03\/71-350x152.jpg 350w\" sizes=\"auto, (max-width: 906px) 100vw, 906px\" \/><figcaption id=\"caption-attachment-266\" class=\"wp-caption-text\">Figure 8.19: Main scenario<\/figcaption><\/figure>\n<table class=\"aligncenter\" style=\"width: 100%;\">\n<caption>Table 8.2: Devices configuration<\/caption>\n<tbody>\n<tr style=\"height: 18px;\">\n<th style=\"width: 137.375px; height: 18px;\" scope=\"col\">Device<\/th>\n<th style=\"width: 330.864px; height: 18px;\" scope=\"col\">IP address<\/th>\n<th style=\"width: 149.42px; height: 18px;\" scope=\"col\">Access<\/th>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 137.375px; height: 18px;\">WebTerm1<\/td>\n<td style=\"width: 330.864px; height: 18px;\">192.168.1.2\/24<\/td>\n<td style=\"width: 149.42px; height: 18px;\">&#8211;<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 137.375px; height: 18px;\">WebTerm2<\/td>\n<td style=\"width: 330.864px; height: 18px;\">172.16.1.2\/24<\/td>\n<td style=\"width: 149.42px; height: 18px;\">&#8211;<\/td>\n<\/tr>\n<tr style=\"height: 141px;\">\n<td style=\"width: 137.375px; height: 141px;\">FortiGate<\/td>\n<td style=\"width: 330.864px; height: 141px;\">Port 1: DHCP Client<\/p>\n<p>Port 2: 172.16.1.1\/24<\/p>\n<p>Port 3: 192.168.1.1\/24<\/td>\n<td style=\"width: 149.42px; height: 141px;\">Port 1: https, ping<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 137.375px; height: 18px;\">Cloud1<\/td>\n<td style=\"width: 330.864px; height: 18px;\"><\/td>\n<td style=\"width: 149.42px; height: 18px;\">&#8211;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ol>\n<li>First, enable VDOMs in the firewall.\n<div class=\"textbox shaded\">\n<p><em>FGVM01TM19008000 # config system global<\/em><\/p>\n<p><em>FGVM01TM19008000 (global) # set vdom-mode multi-vdom<\/em><\/p>\n<p><em>FGVM01TM19008000 (global) # end<\/em><\/p>\n<\/div>\n<\/li>\n<li>Create two VDOMs, <strong>Sales<\/strong> and <strong>Accounting.<\/strong><br \/>\n<figure id=\"attachment_268\" aria-describedby=\"caption-attachment-268\" style=\"width: 450px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-267\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/72.jpg\" alt=\"Create a VDOM sales\" width=\"450\" height=\"130\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/72.jpg 938w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/72-300x86.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/72-768x221.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/72-65x19.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/72-225x65.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/72-350x101.jpg 350w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><figcaption id=\"caption-attachment-268\" class=\"wp-caption-text\">Figure 8.20: Create a VDOM Sales<\/figcaption><\/figure>\n<figure id=\"attachment_268\" aria-describedby=\"caption-attachment-268\" style=\"width: 450px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-268\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/73.jpg\" alt=\"Create a VDOM Accounting\" width=\"450\" height=\"143\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/73.jpg 873w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/73-300x96.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/73-768x245.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/73-65x21.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/73-225x72.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/73-350x111.jpg 350w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><figcaption id=\"caption-attachment-268\" class=\"wp-caption-text\">Figure 8.21: Create a VDOM Accounting<\/figcaption><\/figure>\n<\/li>\n<li>Configure IP addresses for the Interfaces Port2 and Port3. Assign port3 to Sales Vdom and port2 to Accounting Vdom.<br \/>\n<figure id=\"attachment_271\" aria-describedby=\"caption-attachment-271\" style=\"width: 1145px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-269 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/74.jpg\" alt=\"port2 and port3 IP Address configuration\" width=\"1145\" height=\"186\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/74.jpg 1145w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/74-300x49.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/74-1024x166.jpg 1024w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/74-768x125.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/74-65x11.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/74-225x37.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/74-350x57.jpg 350w\" sizes=\"auto, (max-width: 1145px) 100vw, 1145px\" \/><figcaption id=\"caption-attachment-271\" class=\"wp-caption-text\">Figure 8.22: Port2 and Port3 IP address configuration<\/figcaption><\/figure>\n<figure id=\"attachment_271\" aria-describedby=\"caption-attachment-271\" style=\"width: 1129px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-270 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/75.jpg\" alt=\"Port2 Configuration\" width=\"1129\" height=\"477\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/75.jpg 1129w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/75-300x127.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/75-1024x433.jpg 1024w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/75-768x324.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/75-65x27.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/75-225x95.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/75-350x148.jpg 350w\" sizes=\"auto, (max-width: 1129px) 100vw, 1129px\" \/><figcaption id=\"caption-attachment-271\" class=\"wp-caption-text\">Figure 8.23: Port2 configuration<\/figcaption><\/figure>\n<figure id=\"attachment_271\" aria-describedby=\"caption-attachment-271\" style=\"width: 1185px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-271 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/76.jpg\" alt=\"Port3 Configuration\" width=\"1185\" height=\"434\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/76.jpg 1185w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/76-300x110.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/76-1024x375.jpg 1024w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/76-768x281.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/76-65x24.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/76-225x82.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/76-350x128.jpg 350w\" sizes=\"auto, (max-width: 1185px) 100vw, 1185px\" \/><figcaption id=\"caption-attachment-271\" class=\"wp-caption-text\">Figure 8.24: Port3 configuration<\/figcaption><\/figure>\n<\/li>\n<li>Go to <strong>Global VDOM<\/strong> &gt; <strong>Network Interfaces<\/strong> &gt; <strong>Create a new VDOM<\/strong> Link, and configure it as Figure 8.25:<br \/>\n<figure id=\"attachment_272\" aria-describedby=\"caption-attachment-272\" style=\"width: 1192px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-272 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/77.jpg\" alt=\"Create a VDOM link between Sales and Accounting\" width=\"1192\" height=\"777\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/77.jpg 1192w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/77-300x196.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/77-1024x667.jpg 1024w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/77-768x501.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/77-65x42.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/77-225x147.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/77-350x228.jpg 350w\" sizes=\"auto, (max-width: 1192px) 100vw, 1192px\" \/><figcaption id=\"caption-attachment-272\" class=\"wp-caption-text\">Figure 8.25: Create a VDOM link between Sales and Accounting<\/figcaption><\/figure>\n<\/li>\n<li>In Accounting VDOM, Create two static routes:\n<ul>\n<li><strong>Destination: <\/strong>192.168.1.0\/255.255.255.0<\/li>\n<li><strong>Interface:<\/strong> Accounting-Sales<\/li>\n<li><strong>Gateway:<\/strong> 10.10.10.2<\/li>\n<\/ul>\n<figure id=\"attachment_274\" aria-describedby=\"caption-attachment-274\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-273\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/78.jpg\" alt=\"Create a static route in Accounting VDOM\" width=\"400\" height=\"219\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/78.jpg 759w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/78-300x164.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/78-65x36.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/78-225x123.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/78-350x192.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-274\" class=\"wp-caption-text\">Figure 8.26: Create a static route in Accounting VDOM<\/figcaption><\/figure>\n<ul>\n<li><strong>Destination: <\/strong>172.16.1.0\/255.255.255.0<\/li>\n<li><strong>Interface:<\/strong> Accounting-Sales<\/li>\n<li><strong>Gateway:<\/strong> 10.10.10.2<\/li>\n<\/ul>\n<figure id=\"attachment_274\" aria-describedby=\"caption-attachment-274\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-274\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/79.jpg\" alt=\"Create a static route in Accounting VDOM\" width=\"400\" height=\"187\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/79.jpg 889w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/79-300x140.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/79-768x359.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/79-65x30.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/79-225x105.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/79-350x163.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-274\" class=\"wp-caption-text\">Figure 8.27: Create a static route in Accounting VDOM<\/figcaption><\/figure>\n<\/li>\n<li>In Accounting VDOM, Create two Firewall Policies:\n<ul>\n<li><strong>Incoming:<\/strong> Port 2<\/li>\n<li><strong>Outgoing:<\/strong> AS0<\/li>\n<li>NAT Disable<\/li>\n<\/ul>\n<figure id=\"attachment_276\" aria-describedby=\"caption-attachment-276\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-275\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/81.jpg\" alt=\"Create a Firewall Policy in Accounting VDOM from Port2 to AS0\" width=\"400\" height=\"331\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/81.jpg 751w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/81-300x248.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/81-65x54.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/81-225x186.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/81-350x289.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-276\" class=\"wp-caption-text\">Figure 8.28: Create a Firewall Policy in Accounting VDOM from Port2 to AS0<\/figcaption><\/figure>\n<p>Incoming:<\/p>\n<ul>\n<li><strong>Incoming:<\/strong> AS0<\/li>\n<li><strong>Outgoing<\/strong>: Port2<\/li>\n<li>NAT Disable<\/li>\n<\/ul>\n<figure id=\"attachment_276\" aria-describedby=\"caption-attachment-276\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-276\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/80.jpg\" alt=\"Create a Firewall Policy in Accounting VDOM from AS0 to Port2\" width=\"400\" height=\"354\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/80.jpg 714w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/80-300x265.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/80-65x57.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/80-225x199.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/80-350x309.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-276\" class=\"wp-caption-text\">Figure 8.29: Create a Firewall Policy in Accounting VDOM from AS0 to Port2<\/figcaption><\/figure>\n<\/li>\n<li>In Sales VDOM, Create two static routes:\n<ul>\n<li><strong>Destination:<\/strong> 192.168.1.0\/255.255.255.0<\/li>\n<li><strong>Interface:<\/strong> AS1<\/li>\n<li><strong>Gateway:<\/strong> 10.10.10.1<\/li>\n<\/ul>\n<figure id=\"attachment_278\" aria-describedby=\"caption-attachment-278\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-277\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/82.jpg\" alt=\"Create a static route in sales VDOM\" width=\"400\" height=\"227\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/82.jpg 777w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/82-300x170.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/82-768x436.jpg 768w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/82-65x37.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/82-225x128.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/82-350x199.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-278\" class=\"wp-caption-text\">Figure 8.30: Create a static route in Sales VDOM<\/figcaption><\/figure>\n<ul>\n<li><strong>Destination:<\/strong> 172.16.1.0\/255.255.255.0<\/li>\n<li><strong>Interface:<\/strong> AS1<\/li>\n<li><strong>Gateway:<\/strong> 10.10.10.1<\/li>\n<\/ul>\n<figure id=\"attachment_278\" aria-describedby=\"caption-attachment-278\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-278\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/83.jpg\" alt=\"Create a static route in sales VDOM\" width=\"400\" height=\"229\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/83.jpg 738w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/83-300x172.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/83-65x37.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/83-225x129.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/83-350x201.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-278\" class=\"wp-caption-text\">Figure 8.31: Create a static route in Sales VDOM<\/figcaption><\/figure>\n<\/li>\n<li>In Sales VDOM, Create two Firewall Policies:\n<ul>\n<li><strong>Incoming:<\/strong> Port3<\/li>\n<li><strong>Outgoing:<\/strong> AS1<\/li>\n<li><strong>NAT Disable<\/strong><\/li>\n<\/ul>\n<figure id=\"attachment_280\" aria-describedby=\"caption-attachment-280\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-279\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/84.jpg\" alt=\"Create a Firewall Policy in sales VDOM from Port3 to AS1\" width=\"400\" height=\"415\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/84.jpg 655w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/84-289x300.jpg 289w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/84-65x67.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/84-225x233.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/84-350x363.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-280\" class=\"wp-caption-text\">Figure 8.32: Create a Firewall Policy in Sales VDOM from Port3 to AS1<\/figcaption><\/figure>\n<ul>\n<li><strong>Incoming:<\/strong> AS1<\/li>\n<li><strong>Outgoing:<\/strong> Port3<\/li>\n<li>NAT Disable<\/li>\n<\/ul>\n<figure id=\"attachment_280\" aria-describedby=\"caption-attachment-280\" style=\"width: 400px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-280\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/85.jpg\" alt=\"Create a Firewall Policy in sales VDOM from AS1 to Port3\" width=\"400\" height=\"393\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/85.jpg 675w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/85-300x295.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/85-65x64.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/85-225x221.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/85-350x344.jpg 350w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><figcaption id=\"caption-attachment-280\" class=\"wp-caption-text\">Figure 8.33: Create a Firewall Policy in Sales VDOM from AS1 to Port3<\/figcaption><\/figure>\n<\/li>\n<li>Now, you should verify your configuration and should be able to ping from WebTerm1 to WebTerm2.<br \/>\n<figure id=\"attachment_281\" aria-describedby=\"caption-attachment-281\" style=\"width: 711px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-281 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/438\/2023\/08\/86.jpg\" alt=\"you should verify your configuration and should be able to ping from WebTerm1 to WebTerm2\" width=\"711\" height=\"508\" srcset=\"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/86.jpg 711w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/86-300x214.jpg 300w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/86-65x46.jpg 65w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/86-225x161.jpg 225w, https:\/\/opentextbc.ca\/fortigatefirewall\/wp-content\/uploads\/sites\/438\/2023\/08\/86-350x250.jpg 350w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\" \/><figcaption id=\"caption-attachment-281\" class=\"wp-caption-text\">Figure 8.34: Verify configuration<\/figcaption><\/figure>\n<p>To delete a VDOM link in the CLI:<\/p>\n<div class=\"textbox shaded\">\n<p><em>config system vdom-link<\/em><\/p>\n<p><em>delete &lt;VDOM-LINK-Name&gt;<\/em><\/p>\n<p><em>end<\/em><\/p>\n<\/div>\n<\/li>\n<\/ol>\n","protected":false},"author":124,"menu_order":6,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-282","chapter","type-chapter","status-publish","hentry"],"part":245,"_links":{"self":[{"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/pressbooks\/v2\/chapters\/282","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/wp\/v2\/users\/124"}],"version-history":[{"count":1,"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/pressbooks\/v2\/chapters\/282\/revisions"}],"predecessor-version":[{"id":283,"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/pressbooks\/v2\/chapters\/282\/revisions\/283"}],"part":[{"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/pressbooks\/v2\/parts\/245"}],"metadata":[{"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/pressbooks\/v2\/chapters\/282\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/wp\/v2\/media?parent=282"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/pressbooks\/v2\/chapter-type?post=282"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/wp\/v2\/contributor?post=282"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/opentextbc.ca\/fortigatefirewall\/wp-json\/wp\/v2\/license?post=282"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}