Skip to content

Do you really need multiple virtual context (VDOMs/ VSYS)?

Modern firewalls can be split into multiple virtual instances that share the same physical hardware.

The most common reason for doing this is administrative separation. For example, different teams manage different parts of the infrastructure while using the same physical firewall. Another reason is to separate infrastructure areas or environments.

As an instructor and engineer working for a systems integrator, I deal with many different companies. Virtual firewall instances are often already deployed or are being considered for deployment. In my experience, however, in 99% of cases they are not necessary. When I ask why someone uses virtual context, the answer is usually simple: separation. Then I ask another question: is traffic allowed to flow between those virtual context?

Most of the time the answer is yes.

If traffic is allowed to flow between them anyway, what is the real reason for introducing that separation?

Virtual context are great features, but they introduce additional complexity..

Imagine traffic flowing through multiple virtual context. At some point an issue appears and troubleshooting is required at the session level. You have multiple routing tables, multiple session tables, and traffic crossing virtual boundaries. Troubleshooting becomes much more complicated. I have dealt with troubleshooting in multi-VSYS environments many times and, honestly, it is rarely pleasant.

I am not saying that virtual firewall instances are useless or should never be used. My approach as a consultant is simple: infrastructure should follow best practices and be as simple as possible. Simple infrastructure is easier to operate, easier to maintain, and much easier to troubleshoot when something goes wrong. If additional complexity is introduced, there should be a clear reason for it. For example, limiting resources for a specific part of the infrastructure can be a valid justification.

Making a design more complicated just for the sake of being complicated does not make sense. I have seen many environments where additional layers were introduced without delivering any real benefit. Design according to actual requirements, not according to available features. Your future self will thank you during troubleshooting

Join the conversation

Your email address will not be published. Required fields are marked *