NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate 600E is running multiple VDOMs in NAT/route mode. VDOM-1 and VDOM-2 each have an inter-VDOM link interface named 'ivl-1' and 'ivl-2' respectively, and both are assigned IP addresses in the 10.10.10.0/30 subnet. VDOM-1 has a static route to 192.168.2.0/24 via 10.10.10.2, and VDOM-2 has a static route to 192.168.1.0/24 via 10.10.10.1. A user in VDOM-1 (192.168.1.10) cannot ping a server in VDOM-2 (192.168.2.10). What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that inter-VDOM links automatically allow traffic once routes are in place; in reality, firewall policies are still required to permit inter-VDOM traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A firewall policy allowing traffic from VDOM-1 to VDOM-2 is missing.
Inter-VDOM link routing requires three elements: correct IP addressing on the link interfaces, static or dynamic routes in each VDOM pointing to the other VDOM's networks, and a firewall policy permitting traffic between the VDOMs. The scenario indicates that routes are already configured, so the missing piece is the firewall policy. Without it, the FortiGate's default deny action blocks the transit traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A firewall policy allowing traffic from VDOM-1 to VDOM-2 is missing.
Why this is correct
Even with correct routes and inter-VDOM link IPs, traffic between VDOMs is blocked by default. A firewall policy must explicitly permit traffic from the source interface (or zone) in VDOM-1 to the destination interface in VDOM-2. Without such a policy, the FortiGate drops the packets, causing the ping to fail.
- ✗
The inter-VDOM link interfaces must be configured with the same VDOM ID.
Why it's wrong here
Inter-VDOM link interfaces are created as a pair, with each end assigned to a different VDOM. They do not require the same VDOM ID; in fact, they must belong to different VDOMs to provide inter-VDOM connectivity. Assigning the same VDOM ID would defeat the purpose of the link.
- ✗
The inter-VDOM link interfaces do not have 'set allowaccess ping' enabled.
Why it's wrong here
The allowaccess setting controls administrative access to the interface itself (e.g., ping to the interface IP), not transit traffic. A ping from 192.168.1.10 to 192.168.2.10 is transit traffic that is forwarded based on routes and policies. Disabling allowaccess ping would not block transit ICMP.
- ✗
The inter-VDOM link interfaces are not assigned to a zone.
Why it's wrong here
Zones are used for grouping physical or logical interfaces for policy simplification; they are not required for inter-VDOM link routing. The routing between VDOMs relies on IP forwarding and firewall policies, not on zone membership. The absence of a zone would not prevent the ping from working if policies and routes are correct.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.