Fortinet black logo

Cookbook

Adding VDOMs and setting up virtual clustering

Copy Link
Copy Doc ID 4d801240-7ccc-11e9-81a4-00505692583a:708360
Download PDF

Adding VDOMs and setting up virtual clustering

  1. Go to System > Settings > System Operation Settings and enable Virtual Domains.

    Or use the following CLI commands:

    config system global

    set vdom-admin enable

    end

  2. Go to Global > System > VDOM and select Create New to add VDOMs.

    Or use the following CLI commands to add the Engineering VDOM:

    config global

    edit Engineering

    end

  3. Configure virtual clustering and VDOM partitioning on the primary FortiGate. The following commands enables virtual cluster 2, add the Engineering VDOM to virtual cluster 2, and set the virtual cluster 2 device priority of the primary FortiGate to 50.

    config global

    config system ha

    set vcluster2 enable

    config secondary-vcluster

    set vdom Engineering

    set priority 50

    end

    You can also configure virtual clustering and VDOM partitioning from the GUI in Global > System > HA.

  4. Set the virtual cluster 2 priority of the Backup-1 FortiGate to a relatively high value (in this example, 200) so that this FortiGate processes traffic for the VDOMs in virtual cluster 2. The FGCP synchronizes all other HA settings from the primary FortiGate.

    You must use CLI to configure the virtual cluster 2 priority of the backup FortiGate. Use execute ha manage to access the backup FortiGate CLI.

    config global

    config system ha

    config secondary-vcluster

    set priority 200

    end

  5. Set the virtual cluster 2 priority of the Backup-2 FortiGate to 100 so that if the primary FortiGate fails, Backup-2 will become the primary FortiGate but will have the lowest virtual cluster 2 priority. The FGCP synchronizes all other HA settings from the primary FortiGate.

    You must use CLI to configure the virtual cluster 2 priority of the Backup-2 FortiGate. Use execute ha manage to access the backup FortiGate CLI.

    config global

    config system ha

    config secondary-vcluster

    set priority 100

    end

  6. Set the virtual cluster 2 priority of the Backup-3 FortiGate to 150 so that if the backup FortiGate fails, Backup-3 will have the highest virtual cluster 2 device priority. The FGCP synchronizes all other HA settings from the primary FortiGate.

    You must use CLI to configure the virtual cluster 2 priority of the backup FortiGate. Use execute ha manage to access the backup FortiGate CLI.

    config global

    config system ha

    config secondary-vcluster

    set priority 150

    end

Adding VDOMs and setting up virtual clustering

  1. Go to System > Settings > System Operation Settings and enable Virtual Domains.

    Or use the following CLI commands:

    config system global

    set vdom-admin enable

    end

  2. Go to Global > System > VDOM and select Create New to add VDOMs.

    Or use the following CLI commands to add the Engineering VDOM:

    config global

    edit Engineering

    end

  3. Configure virtual clustering and VDOM partitioning on the primary FortiGate. The following commands enables virtual cluster 2, add the Engineering VDOM to virtual cluster 2, and set the virtual cluster 2 device priority of the primary FortiGate to 50.

    config global

    config system ha

    set vcluster2 enable

    config secondary-vcluster

    set vdom Engineering

    set priority 50

    end

    You can also configure virtual clustering and VDOM partitioning from the GUI in Global > System > HA.

  4. Set the virtual cluster 2 priority of the Backup-1 FortiGate to a relatively high value (in this example, 200) so that this FortiGate processes traffic for the VDOMs in virtual cluster 2. The FGCP synchronizes all other HA settings from the primary FortiGate.

    You must use CLI to configure the virtual cluster 2 priority of the backup FortiGate. Use execute ha manage to access the backup FortiGate CLI.

    config global

    config system ha

    config secondary-vcluster

    set priority 200

    end

  5. Set the virtual cluster 2 priority of the Backup-2 FortiGate to 100 so that if the primary FortiGate fails, Backup-2 will become the primary FortiGate but will have the lowest virtual cluster 2 priority. The FGCP synchronizes all other HA settings from the primary FortiGate.

    You must use CLI to configure the virtual cluster 2 priority of the Backup-2 FortiGate. Use execute ha manage to access the backup FortiGate CLI.

    config global

    config system ha

    config secondary-vcluster

    set priority 100

    end

  6. Set the virtual cluster 2 priority of the Backup-3 FortiGate to 150 so that if the backup FortiGate fails, Backup-3 will have the highest virtual cluster 2 device priority. The FGCP synchronizes all other HA settings from the primary FortiGate.

    You must use CLI to configure the virtual cluster 2 priority of the backup FortiGate. Use execute ha manage to access the backup FortiGate CLI.

    config global

    config system ha

    config secondary-vcluster

    set priority 150

    end