nerdexam
Fortinet

NSE4 · Question #255

A FortiGate administrator configures a Virtual Domain (VDOM) for a new customer. After creating the VDOM, the administrator is unable to reassign the dmz interface to the new VDOM as the option is…

The correct answer is A. The dmz interface is referenced in the configuration of another VDOM. An interface cannot be reassigned to a different VDOM if it is currently referenced in the configuration of another VDOM, preventing service disruption.

Submitted by carter_n· Apr 18, 2026FortiGate Deployment and System Configuration

Question

A FortiGate administrator configures a Virtual Domain (VDOM) for a new customer. After creating the VDOM, the administrator is unable to reassign the dmz interface to the new VDOM as the option is greyed out in Web Config in the management VDOM. What would be a possible cause for this problem?

Options

  • AThe dmz interface is referenced in the configuration of another VDOM.
  • BThe administrator does not have the proper permissions to reassign the dmz interface.
  • CNon-management VDOMs can not reference physical interfaces.
  • DThe dmz interface is in PPPoE or DHCP mode.
  • EReassigning an interface to a different VDOM can only be done through the CLI.

How the community answered

(31 responses)
  • A
    81% (25)
  • B
    6% (2)
  • D
    10% (3)
  • E
    3% (1)

Why each option

An interface cannot be reassigned to a different VDOM if it is currently referenced in the configuration of another VDOM, preventing service disruption.

AThe dmz interface is referenced in the configuration of another VDOM.Correct

In a FortiGate VDOM configuration, a physical interface cannot be moved or reassigned to another VDOM if any configuration element (e.g., firewall policy, static route, virtual IP) in its current VDOM is referencing it. The FortiGate greys out the option to prevent breaking existing services and network connectivity.

BThe administrator does not have the proper permissions to reassign the dmz interface.

A greyed-out option typically indicates a functional constraint rather than a permission issue; permission issues usually result in an error message upon attempt.

CNon-management VDOMs can not reference physical interfaces.

Non-management VDOMs are specifically designed to reference and use physical interfaces for traffic segmentation.

DThe dmz interface is in PPPoE or DHCP mode.

An interface's operational mode (PPPoE, DHCP, static) does not inherently prevent its reassignment to a different VDOM, assuming it's not currently in use by other configurations.

EReassigning an interface to a different VDOM can only be done through the CLI.

While the CLI can be used for interface reassignment, it is also possible via the Web Config if no other configuration references the interface, so the option would not be greyed out if this were the only reason.

Concept tested: FortiGate VDOM interface reassignment constraints

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/206536/assigning-interfaces-to-vdoms

Topics

#FortiGate VDOMs#Interface assignment#Configuration dependencies#System configuration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice