Sure, switch was the first thing I removed
 
 Yes I do use Zone for my dual Internet balanced
 
 And I did also employ the professional
 
 Result ... I am as far as I ever was (maybe just a bit closer) to my goal
 So the professional on this occasion helped me only in spiritual way (stating that it should just work)
 
 Which is rather simple (I think)
 
 2 vdoms - root & test
 vlan to vdom test (from Vlan configured AP via vlan trunk across switches to FTG)
 
 connectivity from vdom test to internet via zone in root vdom
 connectivity from vdom test  to selected servers in root vdom
 
 connectivity from vdom root to selected devices in vdom test
 
 Not much to ask, rather simple setup in my mind
 
 Yet me (and the professional) could NOT get the traffic:
 from vdom test to internet zone in root vdom
 to happen at all (it works fine from root vdom ofcourse)
 
 So I gave up & stuck different ADSL line on another port in vdom test
 (reconfiguring the routing ofcourse to reflect this new gateway)
 
 And the results were just fantastic!: 
 could get fine to OpenDNS DNS servers & to Google & to WhatismyIP, but NOT ie. to bbc.co.uk -- even I could trace to bbc.co.uk just fine
 
 So browsing to some sites worked, for others did not (makes no sense at all)
 
 Just to make sure, the FW rule for testing was ALL to ALL ALLOW
 
 Also I could ping my selected root vdom based servers (as well as trace to), but NOT get to webserver on same machine as being pinged (and yes, rules are there to allow PING as well as HTTP /S)
 
 At least I must say it is fun when something behaves completely illogical. Not yet giving up completely, will be still trying...
 
 Seb