System Virtual Domain - Fortinet FortiWiFi FortiWiFi-60 Administration Manual

Antivirus firewalls
Hide thumbs Also See for FortiWiFi FortiWiFi-60:
Table of Contents

Advertisement

System virtual domain

FortiWiFi-60 Administration Guide
FortiWiFi-60 Administration Guide Version 2.80 MR6
FortiWiFi virtual domains provide multiple logical firewalls and routers in a single
FortiWiFi unit. Using virtual domains, one FortiWiFi unit can provide exclusive firewall
and routing services to multiple networks so that traffic from each network is
effectively separated from every other network.
You can develop and manage interfaces, VLAN subinterfaces, zones, firewall policies,
routing, and VPN configuration for each virtual domain separately. For these
configuration settings, each virtual domain is functionally similar to a single FortiWiFi
unit. This separation simplifies configuration because you do not have to manage as
many routes or firewall policies at one time.
When a packet enters a virtual domain on the FortiWiFi unit, it is confined to that
virtual domain. In a given domain, you can only create firewall policies for connections
between VLAN subinterfaces or zones in the virtual domain. Packets never cross the
virtual domain border.
The remainder of FortiWiFi functionality is shared between virtual domains. This
means that there is one IPS configuration, one antivirus configuration, one web filter
configuration, one protection profile configuration, and so on shared by all virtual
domains. As well, virtual domains share firmware versions, antivirus and attack
databases, and user databases. For a complete list of shared configuration settings,
see
"Shared configuration settings" on page
Virtual domains are functionally similar in NAT/Route and in Transparent mode. In
both cases interfaces, VLAN subinterfaces, zones, firewall policies, routing, and VPN
configurations are exclusive to each virtual domain and other configuration settings
are shared. A major difference between NAT/Route and Transparent mode is that in
Transparent mode, interfaces, and VLAN interfaces do not have IP addresses and
routing is much simpler.
The FortiWiFi unit supports 2 virtual domains: root and one addition virtual domain.
This chapter describes:
Virtual domain properties
Virtual domains
Configuring virtual domains
01-28006-0014-20041105
139.
137

Advertisement

Table of Contents
loading

Table of Contents