Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate 600E is deployed with multiple VDOMs in NAT/route mode. The administrator assigns VLAN 100 to VDOM-A on port1 and VLAN 200 to VDOM-B on port1, then configures the VLAN interfaces as management interfaces for each VDOM. Users in VDOM-A report intermittent connectivity to servers in VDOM-B, while pings between the VLAN interface IPs fail. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that VLAN interfaces on the same physical port automatically provide a path between VDOMs, when in fact VDOMs remain isolated until inter-VDOM links and policies are configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No inter-VDOM links or firewall policies exist to permit traffic between VDOM-A and VDOM-B, so the VDOMs are isolated by design.

VDOMs on a FortiGate are isolated routing and security domains. Even when VLAN subinterfaces on the same physical port are assigned to different VDOMs, traffic between those VDOMs does not flow automatically. Inter-VDOM links must be created and firewall policies must allow the traffic in both directions. The failed pings and intermittent connectivity are classic symptoms of missing inter-VDOM routing, not a limitation of VLAN coexistence or management access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    No inter-VDOM links or firewall policies exist to permit traffic between VDOM-A and VDOM-B, so the VDOMs are isolated by design.

    Why this is correct

    By default, VDOMs are isolated from each other. Even though VLAN 100 and VLAN 200 share a physical port, traffic cannot pass between VDOM-A and VDOM-B without an inter-VDOM link (or VDOM link) and firewall policies in each VDOM. Pings between VLAN interface IPs fail because there is no route or policy. Adding inter-VDOM links and policies would enable communication. This is the expected behavior for VDOM isolation.

  • ✗

    Two VLAN interfaces with management access enabled cannot coexist on the same physical interface; the second VDOM's VLAN is silently ignored.

    Why it's wrong here

    FortiGate supports multiple VLAN subinterfaces on a single physical port, even when those VLANs are in different VDOMs. Enabling management access (HTTPS, SSH, PING) on a VLAN interface does not prevent other VLANs from coexisting. The second VLAN is not silently ignored; it appears in its assigned VDOM and can pass traffic. The real issue here is not coexistence but the lack of inter-VDOM routing between the two VDOMs, so connectivity between their subnets fails.

  • ✗

    Management access on a VLAN interface enables the administrative gateway, which overrides inter-VDOM routing and blocks data traffic.

    Why it's wrong here

    Enabling management access on an interface simply allows administrative protocols like HTTPS, SSH, and PING to terminate on that interface. It does not create an administrative gateway that overrides routing, nor does it block data traffic. Inter-VDOM traffic is controlled by inter-VDOM links and firewall policies, not by management access settings. The intermittent connectivity and failed pings point to missing inter-VDOM routing, not a management access conflict.

  • ✗

    VLAN interfaces in different VDOMs on the same physical port require the physical interface to be in a third VDOM with explicit VLAN trunking.

    Why it's wrong here

    FortiGate allows a physical interface to be assigned to one VDOM, and VLAN subinterfaces created on that port can be assigned to different VDOMs. There is no requirement for a third VLAN-trunk VDOM. The physical port belongs to one VDOM, but the VLAN subinterfaces can belong to others. This design is valid and common for shared uplinks. The failure to ping between VLAN interfaces is due to missing inter-VDOM links, not a VLAN trunking limitation.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.