FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ihaidar
Staff
Staff
Article Id 294571
Description This article describes why the VDOM Link Configuration may be lost even if a prefix may be added to the VDOM Link Name.
Scope

FortiGate, VDOM.

FortiOS 6.4.9 and later.

FortiOS 7.0.6 and later.

FortiOS 7.2.0 and later.

Solution

When the VDOM Link Name and the VDOM name are the same, it is upgraded to one of the above-affected versions. The VDOM Link configuration and Firewall policy are lost. To avoid the below issue as a workaround, edit the config file and add a prefix to the existing VDOM Link interfaces.

 

It is important to mention that VDOM Link can have a maximum of 11 characters. Editing the VDOM Link for more than 11 Characters may lead to losing the VDOM Link Configuration when pushing the Configuration file to FortiGate.

 

Example:

 

Assume that the below VDOM Links are configured and in this scenario, the VDOM names are configured exactly the same, and the customer needs to upgrade to one of the above-affected versions. It is necessary in this case to take a backup of the config file, edit the VDOM Links name, push the configuration back to FortiGate, and then start the upgrade to avoid losing of configuration. 

 

config system vdom-link
    edit "VDOM-LINK-1"
    next
    edit "VDOM-LINK-2"
    next
    edit "VDOM-LINK-3"
    next
end

 

But adding a prefix for each of the above VDOM links of (A-) will result in that each name includes 13 characters.

 

Problem:

If the configuration is edited with the below names and pushed to the Configuration File, the VDOM links will be missing.

 

A-VDOM-LINK-1
A-VDOM-LINK-2
A-VDOM-LINK-3

 

Solution:

 

Edit the VDOM Links names with less than or equal to 11 characters.

 

Example of the working edited names:

 

A-VDOM-LINK
A-VDOM-LINK
A-VDOM-LINK

 

Related document: 

VDOM link and policy configuration is lost after upgrading if VDOM and VDOM link have the same name