Multi VDOM mode and the Security Fabric
When operating in Multi VDOM mode, the FortiGate-6000 uses the Security Fabric for communication and synchronization between the management board and FPCs. By default the Security Fabric is enabled but you should not change the security fabric configuration.
You can also verify the default Security Fabric configuration from the CLI:
config system csf
set status enable
set upstream-ip 0.0.0.0
set upstream-port 8013
set group-name "SLBC"
set group-password <password>
set accept-auth-by-cert enable
set management-ip <ip-address>
set management-port 44300
set authorization-request-type serial
set configuration-sync local
set fabric-object-unification default
end
Where <ip-address>
is set to the IP address of the FortiGate-6000 mgmt1 interface.
While operating in Multi VDOM mode, you should not change the Security Fabric configuration from the CLI. And you cannot add the FortiGate-6000 to a Security Fabric. Multi VDOM mode also does not support the Security Rating feature.
The Security Rating feature is available in Split-Task VDOM mode. |
You can go to Security Fabric > Fabric Connectors > Security Fabric Setup to enable and configure FortiAnalyzer logging.
Multi VDOM mode also supports other configurations on the Security Fabric menu, including viewing the Physical Topology and Local Topology and configuring Automation, Fabric Connectors, and External Connectors.