Sure, switch was the first thing I removed
Yes I do use Zone for my dual Internet balanced
And I did also employ the professional
Result ... I am as far as I ever was (maybe just a bit closer) to my goal
So the professional on this occasion helped me only in spiritual way (stating that it should just work)
Which is rather simple (I think)
2 vdoms - root & test
vlan to vdom test (from Vlan configured AP via vlan trunk across switches to FTG)
connectivity from vdom test to internet via zone in root vdom
connectivity from vdom test to selected servers in root vdom
connectivity from vdom root to selected devices in vdom test
Not much to ask, rather simple setup in my mind
Yet me (and the professional) could NOT get the traffic:
from vdom test to internet zone in root vdom
to happen at all (it works fine from root vdom ofcourse)
So I gave up & stuck different ADSL line on another port in vdom test
(reconfiguring the routing ofcourse to reflect this new gateway)
And the results were just fantastic!:
could get fine to OpenDNS DNS servers & to Google & to WhatismyIP, but NOT ie. to bbc.co.uk -- even I could trace to bbc.co.uk just fine
So browsing to some sites worked, for others did not (makes no sense at all)
Just to make sure, the FW rule for testing was ALL to ALL ALLOW
Also I could ping my selected root vdom based servers (as well as trace to), but NOT get to webserver on same machine as being pinged (and yes, rules are there to allow PING as well as HTTP /S)
At least I must say it is fun when something behaves completely illogical. Not yet giving up completely, will be still trying...
Seb