Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate admin configures inter-VDOM routing between VDOM-A and VDOM-B using a VDOM link. The admin wants traffic from VDOM-A to reach a server in VDOM-B. Which three configuration steps are required? (Choose three.)

⚠ Common exam trap

Candidates often assume VDOM links automatically route traffic between VDOMs, but they forget that each VDOM maintains its own independent routing table, so explicit static routes are mandatory for inter-VDOM communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure static routes pointing to the VDOM link interface on both VDOMs

Option E is correct because a VDOM link must first be created and its two ends (interfaces) assigned to VDOM-A and VDOM-B, which provides the physical/logical path for inter-VDOM traffic. Option B is correct because each VDOM needs a static route whose destination is the remote subnet and whose gateway/interface is the local VDOM link interface, so traffic is forwarded across the link. Option C is correct because FortiGate security policies are required to permit traffic between interfaces, so VDOM-A needs a policy allowing traffic from its source interface to the VDOM link interface. Option A is not required because NAT is not needed for inter-VDOM routing when addressing is preserved; NAT could even break return-path routing. Option D is not required because ARP must remain enabled on the VDOM link interfaces for next-hop resolution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable NAT on the VDOM link interface

    Why it's wrong here

    NAT is not required for inter-VDOM routing; the VDOM link forwards traffic between the two routing domains without address translation. It is tempting because NAT commonly accompanies routed traffic, but it is needed only when hiding addresses, not for VDOM-A hosts to reach VDOM-B servers directly.

  • ✓

    Configure static routes pointing to the VDOM link interface on both VDOMs

    Why this is correct

    Each VDOM maintains its own routing table, so both VDOM-A and VDOM-B need static routes whose gateway is the VDOM link interface to reach the peer's subnets. Without these routes, traffic has no path across the link and forwarding fails.

  • ✓

    Configure a firewall policy on VDOM-A allowing traffic to the VDOM link interface

    Why this is correct

    Firewall policies are evaluated per VDOM, so VDOM-A requires a policy permitting traffic from its internal interface to the VDOM link interface. Without this policy, inter-VDOM traffic is dropped before it can traverse the link to VDOM-B.

  • ✗

    Disable ARP on the VDOM link interfaces

    Why it's wrong here

    ARP operates normally on VDOM link interfaces; disabling it prevents the peer interface from resolving link-layer addresses, breaking forwarding. It is tempting as a security hardening step, but ARP must remain enabled for the two VDOM link ends to exchange traffic across the link.

  • ✓

    Create a VDOM link and assign an interface to each VDOM

    Why this is correct

    A VDOM link creates the virtual point-to-point connection between VDOMs, and each end must be assigned as an interface within its respective VDOM. This provides the physical-layer path that inter-VDOM routing and policies then operate over.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.