Hello,
I have recently taken over a site that has a Pair of FortiGate 100F's (6.4.8). Looking at the GUI I see VDOMs are not enabled. When I query the Sys Global Full Config VDOM-MODE is set to NO-VDOM. However when I query the System Interfaces I see that the MGMT Port is not on the Root VDOM. I believe the prior person manually set this and setup IPs so he could manage each unit separately via the MGMT Port as each has it's own IP and HTTPS and Management enabled. Is there some documentation on setting this up or did he just do this himself. Is this a viable config or will there be possible issues to look for?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Dear Rich,
the dmgmt_vdom is a dedicated management vdom where interfaces with 'dedicated-to management' go into, same as vsys_hamgmt is is the dedicated HA management vdom.
Even with vdoms enabled, the vsys_hamgmt and dmgmt_vdom still technically exist and can't be deleted.
If you unset the 'dedicated-to management' option in the interface, it should return to root VDOM.
Hope this helps!
Hi
The device should use the Technical Tip: HA Reserved Management Interface feature.
You will find that the independently managed HA Reserved Management interface looks like an independent lightweight VDOM, which is isolated from the root VDOM, have an independent routing, so that the feature of independent network management two HA FGT can be realized
Thanks
Kangming
Thanks for the reply I did look at this and it does not appear this is enabled as it show off when I connect to the HA Master and Edit. I really think he just went into the CLI and manually put the VDOM of the MGMT interface on a different named vdom
You are welcome.
How do you see multiple VDOMs, if you do not enable VDOM, there is no way to add interfaces to other VDOM, there is the only root in CLI/GUI.
Thanks
Kangming
From the CLI:
#show sys interfaces
Yeah, It looks really strange, you can share the configuration below ha
# config system ha
# show
Thanks
Kangming
Here is what is below the HA Config very basic
Check if this VDOM is configured in other places:
# show full-configuration | grep -f dmgmt-vdom
Thanks
Kangming
This is the only Place:
#dedicated-management=dmgmt-vdom <---
config system interface
edit "mgmt"
set vdom "dmgmt-vdom" <---
Dear Rich,
the dmgmt_vdom is a dedicated management vdom where interfaces with 'dedicated-to management' go into, same as vsys_hamgmt is is the dedicated HA management vdom.
Even with vdoms enabled, the vsys_hamgmt and dmgmt_vdom still technically exist and can't be deleted.
If you unset the 'dedicated-to management' option in the interface, it should return to root VDOM.
Hope this helps!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.