Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate has two VDOMs: 'root' and 'customer'. The admin wants to route traffic from 'customer' to the internet via 'root', which has a BGP connection to an ISP. What is the required configuration?

⚠ Common exam trap

Watch out — candidates often assume VDOMs can route traffic to each other simply by configuring static routes or using a shared interface, but FortiGate requires a dedicated inter-VDOM link with firewall policies to enable inter-VDOM traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an inter-VDOM link between 'customer' and 'root', and configure policies to allow traffic

Inter-VDOM links are the only supported method for routing traffic between VDOMs on the same FortiGate. An inter-VDOM link creates a virtual point-to-point connection between two VDOMs, allowing traffic to flow through firewall policies. Without this link, VDOMs are isolated and cannot exchange traffic, even if static routes or BGP are configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable VDOM forwarding on the WAN interface in 'root'

    Why it's wrong here

    VDOM forwarding is a global setting enabling inter-VDOM links, not routing between VDOMs. Traffic from 'customer' to 'root' requires an inter-VDOM link plus static routes in both VDOMs, since each VDOM maintains its own routing table. VDOM forwarding would be relevant only when linking VDOMs via shared interfaces.

  • ✗

    Configure a static route in 'customer' pointing to the 'root' VDOM's management IP

    Why it's wrong here

    A static route cannot point to another VDOM's management IP; inter-VDOM routing requires a link or the root VDOM as next-hop via an inter-VDOM link. It is tempting because static routes normally forward traffic, but that mechanism applies within a VDOM, not across VDOM boundaries.

  • ✗

    Place both VDOMs in the same VDOM group and enable route leak

    Why it's wrong here

    VDOM groups share routing and firewall policy but do not provide route leaking between separate VDOMs; inter-VDOM routing needs an inter-VDOM link. Grouping is tempting because it simplifies shared configuration, yet it would be correct only for VDOMs intended to share identical policy, not for routing customer traffic out via root.

  • ✓

    Create an inter-VDOM link between 'customer' and 'root', and configure policies to allow traffic

    Why this is correct

    An inter-VDOM link provides the Layer 3 path between 'customer' and 'root', since VDOMs have separate routing tables. Firewall policies on both VDOMs must then permit the traffic, allowing 'customer' to reach the internet via root's BGP-learned default route.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.