Skip to main content
canoas
Visitor III
February 9, 2026
Question

How to unset a VDOM on mgmt interface

  • February 9, 2026
  • 6 replies
  • 595 views

I would like to independent IP addresses on my  "mgmt" interfaces in my cluster Active-Passive.

 

Every time I configure an IP on one cluster "mgmt" interface, then the Passive unit inherits this IP addresses which is what I do not want. My aim is to have dedicated IP addresses for "mgmt" on each cluster and use port2 (mgmt) as the mgmt interfaces with the same IP address.

 

How can I remove/unset a vdom from "mgmt" (unset vdom root)I have  been looking for dependencies to delete and have run out of ideas! Removed dedicated mgmt cmd, under config sys global removed unset mgmt-vdom which I don't think was going to help.

Deleted config firewall address dependency as well.

 

Thanks!

6 replies

Toshi_Esumi
SuperUser
SuperUser
February 9, 2026

That means you are NOT configuring "mgmt" interface under Management Interface Reservation in GUI, or config ha-mgmt-interfaces under config sys ha in CLI.
Either way, you need to configure the common GW IP there for buth units.

Toshi

canoas
canoasAuthor
Visitor III
February 9, 2026

oh, yes I configured port2 under mgmt int reservation in HA, let me have a look in the office tomorrow morning and I will reply back. Thanks.

 

Also, I configured the Mgmt interface in a another VDOM just to test if I could unset the VDOM, problem is now, I can't seem to change this back to "set vdom root". Dependencies I guess?  Or if I add mgmt to reservation, will the VDOM be removed? I guess this is not the case.

Toshi_Esumi
SuperUser
SuperUser
February 9, 2026

You need to clean up those before you can set "mgmt" as dedicated management interface. It would probably reject or doesn't show up as an option. It shouldn't be anywhere in any VDOM config.

Toshi

canoas
canoasAuthor
Visitor III
February 10, 2026

I cleaned up the dependencies, reconfigured as follows:

 

"mgmt" interface configured as .10

config router static

set interface mgmt

gateway .1

 

after this could ping .10

 

configured port2 as dedicated mgmt on both units

.8 on Primary 

.9 on Secondary

 

config ha-mgmt-interface
edit 1
set interface port2
set gateway .1
next

 

Results:

can ping .9 and access GUI port2 (Secondary)

can ping .10 and access GUI mgmt (Mgmt cluster)

cannot ping .8 (Primary port2)

HA Primary is Primary HA in tact, sync etc

Not sure why I cannot ping .8, rebooted both units.

HA is working fine

on each port 2 interface allowaccess ping, ssh, HTTPS, FMG

port2 is configured identically apart from .8 and .9

static router static is the same for both

except 120 priority of Primary and 115 for Secondary

 

NB: I originally configured the Secondary by mistake as .8 not intended, only thought is perhaps the switch has the mac of the secondary, most switch arp table timers are quite long, but rebooting both boxes I would envisage would clear arp correctly.

 

Is there any reason why I cannot ping .8 the Primary

ntp server uses "mgmt"

 

Thanks.  

Toshi_Esumi
SuperUser
SuperUser
February 10, 2026

You've completely confused me. You can off course reserve two interfaces, like port2 and mgmt, for HA's management interface(s). But you can't have two physical interfaces in the same subnet. They have to have different subnets with different GWs.
Not sure what you're trying to accomplish with two interfaces on each unit.

Toshi

ede_pfau
SuperUser
SuperUser
February 9, 2026

Seems you are actively fighting VDOMs. Sometimes, there is a discrepancy between what your vision is (based on other equipment) and what FortiOS offers.

 

FortiOS comes with a "root" VDOM regardless if you activate multi-vdom mode or not. This is the designated management VDOM through which all 'local-in' and 'local-out' traffic is traversing. From scratch, all interfaces belong to "root".

You can transfer the management role to an additional VDOM, other than "root". For instance, to run it in Transparent Mode. IMHO this would be a corner case.

If you can't get back from using the new VDOM then there are references to that VDOM. This can be tedious to find, depending on what you did and how intensive the OS was, er, restructured. One definite way out is "exec factoryreset".

 

It doesn't need to be that complicated. Maybe have another look at the Admin Guide for the concepts in FortiOS, and HA setup in particular. We _all_ crave for independent IP addresses for managing a cluster and its members. It does work.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!