NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate 600E is configured with multiple VDOMs in NAT mode. The administrator wants to route traffic between VDOM-1 and VDOM-2 without using physical interfaces. They create a VDOM link named 'vlink' with interfaces vlink0 and vlink1, assign vlink0 to VDOM-1 (IP 10.0.1.1/30) and vlink1 to VDOM-2 (IP 10.0.1.2/30). However, traffic from a host in VDOM-1 (192.168.1.0/24) to a server in VDOM-2 (192.168.2.0/24) fails. The administrator has added static routes in both VDOMs pointing to the respective VDOM link IPs. What is the most likely cause of the failure?
⚠ Common exam trap
The trap here is assuming that VDOM links automatically permit traffic once routes are in place, ignoring the need for explicit firewall policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VDOM link interfaces require a firewall policy to allow traffic between VDOMs.
Inter-VDOM routing via VDOM links requires both routing and firewall policies. The VDOM link provides the Layer 3 path, and static routes direct traffic, but without a firewall policy allowing traffic from the source to destination VDOM, the FortiGate drops the packets. The administrator must add a policy in VDOM-1 (and possibly VDOM-2 for return traffic) to permit the flow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VDOM link interfaces must be in the same VDOM.
Why it's wrong here
VDOM link interfaces are specifically designed to connect two different VDOMs; each end must reside in a separate VDOM. Placing both ends in the same VDOM would defeat the purpose and is not a supported configuration. The failure is not due to this, as the administrator correctly assigned each interface to a different VDOM.
- ✓
The VDOM link interfaces require a firewall policy to allow traffic between VDOMs.
Why this is correct
Even with VDOM links and static routes, inter-VDOM traffic is subject to firewall policies. By default, no policy exists to permit traffic from VDOM-1 to VDOM-2 across the VDOM link. The administrator must create a firewall policy in each VDOM (or at least in the initiating VDOM) to allow the traffic, otherwise it will be dropped.
- ✗
The IP addresses on the VDOM link interfaces must be in different subnets.
Why it's wrong here
VDOM link interfaces function like a point-to-point connection and must be in the same subnet to communicate. Using different subnets would prevent direct routing between the two interfaces. The administrator correctly assigned IPs in the same /30 subnet, so this is not the issue.
- ✗
The static routes must be configured with the VDOM link interface as the outgoing interface, not the next-hop IP.
Why it's wrong here
Static routes can use either a next-hop IP or an outgoing interface, but using the next-hop IP is valid and common. Specifying the interface alone is not required and would not cause failure if the next-hop is correct. The real problem is the missing firewall policy that permits inter-VDOM traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.