Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MSmeltzer
New Contributor

Does VDOM creation disrupt root VDOM

I have a question regarding creating a VDOM. I have been using the root vdom for our environment, but would like to test if flow mode might be better, so looking to setup a new vdom with flow mode enabled. If I create a Flow based vdom does this disrupt any of my policies on the root vdom.

 

Speaking of the root vdom, should this be used, or should this be left alone and a VDOM setup for what we are using the root vdom for?

 

1st of many questions to come :)

 

Thanks in advance.

 

Matt

 

 

2 Solutions
Michael_McDonnell
New Contributor III

In my experience, the creation of a VDOM does not disrupt the root VDOM. You will have to re-assign interfaces to the new VDOM. If those interfaces are currently in use in the root VDOM, you will need to remove all references to them.

 

The first time you enable VDOM mode, you will be logged out of the GUI/CLI when the changes are applied. It will not reboot the FortiGate... just log out all admin sessions.

 

The first time your create a new VDOM, everything gets separated into "global" settings and VDOM settings. Most of your policies/settings get migrated to the "root" VDOM.

 

If you are managing your FortiGate with a FortiManager, then creating a new VDOM may be... confusing. Changes made via the FortiManager to a single VDOM often cause policy and device configuration changes that appear to affect all VDOMs (this is really just changing some interface related things). It may be best to make the changes on the FortiGate and then re-import your configurations for each other VDOM. 

View solution in original post

emnoc
Esteemed Contributor III

No, the enabling or adding or deleting   a VDOM will not effect  "root" vdom.

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
3 REPLIES 3
Michael_McDonnell
New Contributor III

In my experience, the creation of a VDOM does not disrupt the root VDOM. You will have to re-assign interfaces to the new VDOM. If those interfaces are currently in use in the root VDOM, you will need to remove all references to them.

 

The first time you enable VDOM mode, you will be logged out of the GUI/CLI when the changes are applied. It will not reboot the FortiGate... just log out all admin sessions.

 

The first time your create a new VDOM, everything gets separated into "global" settings and VDOM settings. Most of your policies/settings get migrated to the "root" VDOM.

 

If you are managing your FortiGate with a FortiManager, then creating a new VDOM may be... confusing. Changes made via the FortiManager to a single VDOM often cause policy and device configuration changes that appear to affect all VDOMs (this is really just changing some interface related things). It may be best to make the changes on the FortiGate and then re-import your configurations for each other VDOM. 

MSmeltzer

Thanks Michael. I ll go ahead and make a new VDOM, no downfall of keeping the root VDOM going as is right now I suspect, I'll create a new VDOM I would like to try out flow mode. I ll make a new WAN / LAN interface for the new VDOM. Appreciate your help.

 

Matt

emnoc
Esteemed Contributor III

No, the enabling or adding or deleting   a VDOM will not effect  "root" vdom.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors