FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kgeorge
Staff
Staff
Article Id 337884
Description

 

This article describes how to delete VDOM(s) in the GUI when they cannot be deleted despite not being used anywhere in the FortiGate.

 

Scope

 

FortiGate, VDOM.

 

Solution

 

 

  1. In the screenshot below, the VDOM 'Klint1' is not referenced in any configuration in the FortiGate. It should therefore be possible to delete it using the 'Delete' option. However, the 'Delete' option is greyed out.

 

 

Delete_Greyed.png

 

 

  1. Selecting the 'Ref count 15' brings up the following screen, which clearly shows that this VDOM is not used anywhere, and that the number of objects is only 5.

 

 

RefCount.png

 

 

  1. The right information related to Object dependencies for this VDOM 'Klint1' which is 'Ref count' can be seen via the CLI using the command 'diagnose sys cmdb refcnt show system.vdom.name Klint1'.

 

 

RefCount_CLI.png

 

   4. Though there are actual number of references showing via CLI, it should not stop us from deleting the VDOM as the 'admin' user belongs to 'root' vdom.

 

AdminUser.png

 

  1. To resolve this, open the VDOM 'Klint1', switch the Type from 'Traffic' to 'Admin', select OK and toggle back to 'Traffic' and select OK.

  2. It can be seen that, the 'Ref count' is updated appropriately after that and also, the 'Delete' option will be available.

 

 

Delete_enabled.png

Note: Before deleting the VDOM, make sure that the VDOM is not used in any configuration of the FortiGate. As a good practice, back up the Configuration file before making any changes.

Contributors