Skip to main content
HS08
Contributor III
September 17, 2025
Solved

VDOM Global

  • September 17, 2025
  • 3 replies
  • 443 views

If the Fortigate have multiple vdom, can we directly enter to the vdom global without issuing 'config global'?

Currently when i ssh to the fortigate i must enter that command first before i can execute 'get system global'

Best answer by Toshi_Esumi

I think your question is not to FGT side but to Ansible side, which I don't know well.
But there should be some discussion how to interactively exchange commands and get responses over SSH using Ansible. My quick search found this.
https://forum.ansible.com/t/make-an-ssh-connection-and-run-a-command-from-within-the-playbook/36256/3

Toshi

3 replies

Toshi_Esumi
SuperUser
SuperUser
September 17, 2025

No you can not.
The landing place of SSH or console you get in as a super_admin is not in either "global" or any "vdom" in multi-vdom environment, where is the only place you can "show" the entire config for both global and all vdoms.

To see/edit any config in global like "config system global", you have to get in "config global".

 

Toshi

HS08
HS08Author
Contributor III
September 17, 2025

So we cannot access to the global directly after successfull login via cli?

My point is we have ansible to query to the fortigate and the playbook will run get system global without typing config global.

Toshi_Esumi
SuperUser
SuperUser
September 17, 2025

I think your question is not to FGT side but to Ansible side, which I don't know well.
But there should be some discussion how to interactively exchange commands and get responses over SSH using Ansible. My quick search found this.
https://forum.ansible.com/t/make-an-ssh-connection-and-run-a-command-from-within-the-playbook/36256/3

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!