Multi VDOM configuration examples

The following examples show how to configure per-VDOM settings, such as operation mode, routing, and security policies, in a network that includes the following VDOMs:

  • VDOM-A: allows the internal network to access the Internet.
  • VDOM-B: allows external connections to an FTP server.
  • root: the management VDOM.

You can use VDOMs in either NAT or transparent mode on the same FortiGate. By default, VDOMs operate in NAT mode.

For both examples, multi VDOM mode must be enabled, and VDOM-A and VDOM-B must be created.

Enable multi VDOM mode

Multi VDOM mode can be enabled in the GUI or CLI. Enabling it does not require a reboot, but does log you out of the device. The current configuration is assigned to the root VDOM.


On VMs and FortiGate 60 series models and lower, VDOMs can only be enabled using the CLI.

To enable multi VDOM mode in the GUI:
  1. On the FortiGate, go to System > Settings.
  2. In the System Operation Settings section, enable Virtual Domains.
  3. Select Multi VDOM for the VDOM mode.
  4. Click OK.
To enable multi VDOM mode with the CLI:

config system global

set vdom-mode multi-vdom


Create the VDOMs

To create the VDOMs in the GUI:
  1. In the Global VDOM, go to System > VDOM and click Create New.
  2. In the Virtual Domain field, enter VDOM-A.

  3. If required, set the NGFW Mode. If the NGFW Mode is Profile-based, Central SNAT can be enabled.
  4. Click OK to