Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
5q46n2te8jPWJY
New Contributor III

Move content from root VDOM to VDOM1

Hello,

 

I need to set up VDOMs on an existing installation. I have enabled VDOMs on the Fortigate, so I can see the root VDOM. I have created a VDOM1, and I want to completely move the contents of the root VDOM to VDOM1 (the VLANs, the rules associated with the VLANs, etc.). How can I do this simply and cleanly? I also have FortiManager available.

 

In the future, I will need to create other VDOMs, which is why I want to move the contents from root to VDOM1.

 

Thank you for your help!

1 Solution
fricci_FTNT
Staff
Staff

Hi @5q46n2te8jPWJY ,


One way it to get in contact with your SE and through Professional Services they might be able to help.

 

A feasible way on your own could be exporting a backup copy of the config from GUI, editing it and moving/reassigning the desired contents from root VDOM to VDOM1, then restoring the new config file from GUI. Bear in mind that if you do something incorrectly, you might really damage the config (so keep a second backup copy untouched on a side). You might also lose access to your FortiGate.
I do not recommend you to do it.

Once done, you also need to re-import/re-sync the FortiGate config into FortiManager. If that does not work, you have to delete the unit from FortiManager and reimport it from scratch.

Be aware that playing with the config file can be dangerous and can harm your FortiGate if you are not aware of what you are exactly doing.

Best regards,

---
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.

View solution in original post

3 REPLIES 3
birotba3
New Contributor

Certain unit-wide processes run in the context of the management VDOM. DNS lookup is one thing - all the VDOMs use the management VDOM for DNS resolution. Another is SNMP; if you want to query the unit by SNMP/receive SNMP traps, you must use interfaces assigned to the management VDOM https://mobdro.bio/ .

ede_pfau

...all of which does not present any reason against moving root to VDOM1 - you only have to configure VDOM1 as your management VDOM (global: conf sys global).

IMHO a lot of hassle. I don't see why you couldn't live with the root VDOM.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
fricci_FTNT
Staff
Staff

Hi @5q46n2te8jPWJY ,


One way it to get in contact with your SE and through Professional Services they might be able to help.

 

A feasible way on your own could be exporting a backup copy of the config from GUI, editing it and moving/reassigning the desired contents from root VDOM to VDOM1, then restoring the new config file from GUI. Bear in mind that if you do something incorrectly, you might really damage the config (so keep a second backup copy untouched on a side). You might also lose access to your FortiGate.
I do not recommend you to do it.

Once done, you also need to re-import/re-sync the FortiGate config into FortiManager. If that does not work, you have to delete the unit from FortiManager and reimport it from scratch.

Be aware that playing with the config file can be dangerous and can harm your FortiGate if you are not aware of what you are exactly doing.

Best regards,

---
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors