Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
security22
New Contributor II

Disabling VDOM mode affects policies?

We have a FortiGate with multiple VDOMs (root, global, VDOM1, VDOM2) and would like to convert it back to no VDOM mode with configurations from VDOM1 that is having production traffic. Is this action possible by removing all configurations in VDOM2 and setting it back to no VDOM mode?

 

If it's possible, what are the commands/actions that needs to be done for this?

 

 

6 REPLIES 6
ErrantOsi
New Contributor III

When converting from no VDOM to VDOM mode you lose nearly all configuration (policies etc. disappear). I guess its the same when you do it vice versa.

mle2802
Staff
Staff

Hi @security22,
You can move all the references to root VDOM and then delete those VDOMs. After that, you can disable multi-vdom and this will not affect root VDOM.

security22
New Contributor II

Hi there, thanks for the input. 

 

I understand that when moving interfaces back to root VDOM, all references must be deleted. Correct me if I'm wrong, this includes configurations under the Policies & Object? 

 

Are there any method to move these configurations to root VDOM without deleting the configurations? Or do I need to manually configure all these rules from scratch?

AEK

As one of the possible method I'd probably do that:

  1. Backup the full configuration
  2. Edit the backup file to merge the whole config to one VDOM and remove the other VDOMs
  3. Schedule a 2h downtime
  4. Restore the new configuration to my firewall
  5. In case of errors, correct the config and restore again
  6. Perform all the required validation tests
  7. Roll-back (restore original config) in case of failure

In case you have a spare FGT then you will have all the time to work on it.

Or if you have HA config then you can spit your cluster so you can have all the time to work on the second node.

AEK
AEK
security22
New Contributor II

Hi there, thanks for the input. We'll test this out in a lab environment and update any progress.

AEK
SuperUser
SuperUser

There no specific command to move the config from one vdom to another, but you must study the case, prepare the plan then manually move the config to target vdom.

Take a full backup of your current confiig, so in case the migration fails you'll ba able to rollback easily and quickly.

AEK
AEK
Labels
Top Kudoed Authors