After changing the VDOM containing the IPsec tunnel interface on the FortiGate 60F (firmware version 7.4.3) to a non-management VDOM, the IPsec tunnel went down upon reboot. Prior to the reboot, the tunnel remained up.
After switching the VDOM back to the management VDOM, the tunnel came back up without any other changes.
Is there a requirement that the IPsec tunnel interface must be under the management VDOM at boot time in order to come up?
You need to share how exactly you "moved" the IPsec to another VDOM.
My first question is how the new VDOM can get to the internet. Via the original VDOM interface after getting to it via vdom-link/npu-vlink? Where is the SNAT point? Or did you "move" the physical internet interface/port to the new VDOM? Did the public IP changed? and so on.
Toshi
Created on ‎09-12-2025 09:08 PM Edited on ‎09-12-2025 09:14 PM
Thank you for your reply.
This is a preliminary response.
I changed the management VDOM from the one originally hosting the IPSec tunnel interface to another VDOM, using the method described in the following URL: Fortinet Administration Guide – Management VDOM.
This change alone did not cause the tunnel to go down. However, after rebooting the device in this state, the IPSec tunnel went down. When I switched the management VDOM back to the original VDOM where the tunnel resides—using the same method—the tunnel came back up.
I did not move the interface from its current VDOM to another VDOM. Instead, I designated a different VDOM—one that does not contain the interface—as the management VDOM, and removed the management role from the VDOM where the interface actually resides.
Created on ‎09-13-2025 02:34 AM Edited on ‎09-13-2025 02:37 AM
in theory, change in management vdom should not have impact in the VDOM for IPsec as long as the interface IP ( IPsec IP remote/local remain the same ) / route ( a route for reaching the remote GW is valid and installed in RIB [ get router info routing-table details IP ] ) / firewall rules are in place and correct ( if the management interface is part of the IPsec config , in any of the previous mentioned , could be a factor of why it remains down since it's not used anymore/down ) .
if not, i would say that it's a coincidence and would recommend doing a debug of the down state of the IPsec tunnel as described here, https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPN-tunnels/ta-p/195955
In addition to what @funkylicious explained and suggested, I just want to make sure your new management vdom has internet connection. It wouldn't impact the IPsec on the other vdom. But a management vdom needs to reach FortiGuard services for the FGT unit to operate.
Toshi
Thank you all for your responses. I'm reviewing each reply carefully, so I apologize for the delay in getting back to you.
First, in response to Toshi-san: all the VDOMs mentioned in my question do not have internet connectivity. The IPSec tunnel interface is connected to a remote IPv6 address via NGN-VPN. I also find it unclear why the status of the tunnel interface—whether it is up or down—would be affected by whether the VDOM it belongs to is designated as the management VDOM or not.
Thank you again for your continued support.
User | Count |
---|---|
2571 | |
1365 | |
796 | |
652 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.