NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate 600E is running in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator assigns physical port3 to VDOM-1 as a dedicated interface, then creates a VLAN subinterface (VLAN 100) on port3 for VDOM-2. After configuration, VLAN 100 traffic is dropped even though the VLAN interface is up. Which action resolves the issue?
⚠ Common exam trap
The trap here is assuming that a subinterface can be placed in a different VDOM than its parent interface, which is not supported on FortiGate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create the VLAN 100 subinterface inside VDOM-1, where the parent interface resides, rather than in VDOM-2.
On FortiGate, VLAN subinterfaces inherit the VDOM membership of their parent physical interface. Because port3 is assigned to VDOM-1, VLAN 100 must also be created within VDOM-1. Creating it under VDOM-2 leaves the traffic unhandled in the VDOM that actually receives the frames, so frames are dropped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a VDOM link between VDOM-1 and VDOM-2 and route VLAN 100 traffic through the link.
Why it's wrong here
A VDOM link provides a virtual point-to-point connection between two VDOMs for inter-VDOM routing, but it does not solve the problem of a VLAN subinterface existing in the wrong VDOM. Traffic tagged VLAN 100 arriving on port3 would still be processed in VDOM-1, where no matching VLAN interface exists.
- ✗
Enable the vlan-forwarding setting under config system interface on port3.
Why it's wrong here
The vlan-forwarding option controls whether VLAN-tagged frames received on a physical interface are forwarded to the CPU for software processing; it is used for VLANs not defined as subinterfaces, not for enabling a subinterface assigned to a different VDOM. Enabling it here does not let a VDOM use a subinterface of an interface belonging to another VDOM.
- ✗
Assign the physical port3 interface to VDOM-2 as well, using the same interface in both VDOMs.
Why it's wrong here
A physical interface can only belong to one VDOM at a time on a FortiGate. You cannot assign the same physical interface to two different VDOMs simultaneously; attempting this fails or requires the interface to be moved. The subinterface must instead be created directly inside the VDOM that owns the parent interface.
- ✓
Create the VLAN 100 subinterface inside VDOM-1, where the parent interface resides, rather than in VDOM-2.
Why this is correct
VLAN subinterfaces must be created on the parent interface within the same VDOM that owns the parent. Since port3 belongs to VDOM-1, VLAN 100 must be defined in VDOM-1. If VDOM-2 needs separate VLAN traffic, the parent interface should be shared or a different physical interface used in VDOM-2.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.