Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate 600E is running multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 each have an inter-VDOM link interface named 'ivl-1' and 'ivl-2' respectively, and both are assigned IP addresses in the 10.10.10.0/30 subnet. VDOM-1 has a static route to 192.168.2.0/24 via 10.10.10.2, and VDOM-2 has a static route to 192.168.1.0/24 via 10.10.10.1. A user in VDOM-1 (192.168.1.10) cannot ping a server in VDOM-2 (192.168.2.10). What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that inter-VDOM links automatically allow traffic once routes are in place; in reality, firewall policies are still required to permit inter-VDOM traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A firewall policy allowing traffic from VDOM-1 to VDOM-2 is missing.

Inter-VDOM link routing requires three elements: correct IP addressing on the link interfaces, static or dynamic routes in each VDOM pointing to the other VDOM's networks, and a firewall policy permitting traffic between the VDOMs. The scenario indicates that routes are already configured, so the missing piece is the firewall policy. Without it, the FortiGate's default deny action blocks the transit traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A firewall policy allowing traffic from VDOM-1 to VDOM-2 is missing.

    Why this is correct

    Even with correct routes and inter-VDOM link IPs, traffic between VDOMs is blocked by default. A firewall policy must explicitly permit traffic from the source interface (or zone) in VDOM-1 to the destination interface in VDOM-2. Without such a policy, the FortiGate drops the packets, causing the ping to fail.

  • ✗

    The inter-VDOM link interfaces must be configured with the same VDOM ID.

    Why it's wrong here

    Inter-VDOM link interfaces are created as a pair, with each end assigned to a different VDOM. They do not require the same VDOM ID; in fact, they must belong to different VDOMs to provide inter-VDOM connectivity. Assigning the same VDOM ID would defeat the purpose of the link.

  • ✗

    The inter-VDOM link interfaces do not have 'set allowaccess ping' enabled.

    Why it's wrong here

    The allowaccess setting controls administrative access to the interface itself (e.g., ping to the interface IP), not transit traffic. A ping from 192.168.1.10 to 192.168.2.10 is transit traffic that is forwarded based on routes and policies. Disabling allowaccess ping would not block transit ICMP.

  • ✗

    The inter-VDOM link interfaces are not assigned to a zone.

    Why it's wrong here

    Zones are used for grouping physical or logical interfaces for policy simplification; they are not required for inter-VDOM link routing. The routing between VDOMs relies on IP forwarding and firewall policies, not on zone membership. The absence of a zone would not prevent the ping from working if policies and routes are correct.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.