Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to allow a server in VDOM-A to be accessed from the internet through VDOM-B, which has the public IP address. The administrator has already created a VDOM link between VDOM-A and VDOM-B. Which additional configuration is required to make the server accessible?

⚠ Common exam trap

The trap here is assuming that inter-VDOM routing and firewall policies alone are sufficient, overlooking the need for destination NAT via a VIP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a VIP on VDOM-B that maps the public IP to the server's private IP, and ensure firewall policies allow the traffic in both VDOMs.

To allow external access to a server behind a FortiGate with multiple VDOMs, a VIP must be configured on the VDOM with the public IP to perform destination NAT. Firewall policies in both VDOMs must permit the traffic, and the VDOM link carries the translated packets. Without the VIP, the server would not receive the traffic correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a firewall policy in VDOM-B that allows incoming traffic to the VDOM link interface and a policy in VDOM-A that allows traffic from the VDOM link to the server.

    Why it's wrong here

    While policies are necessary, they alone do not translate the public IP to the server's private IP. The traffic must also be NATed. Without destination NAT on VDOM-B, the server would receive packets with the public IP as destination and likely drop them. This option omits the essential NAT configuration.

  • ✗

    Create a central SNAT policy in VDOM-B to translate the public IP to the server's private IP, and apply it to the VDOM link.

    Why it's wrong here

    Central SNAT is used for source NAT, not destination NAT. Translating the public IP to the server's private IP is a destination NAT operation, which requires a VIP. Central SNAT would change the source address of outbound traffic, not enable inbound access to an internal server.

  • ✓

    Configure a VIP on VDOM-B that maps the public IP to the server's private IP, and ensure firewall policies allow the traffic in both VDOMs.

    Why this is correct

    A VIP (Virtual IP) on VDOM-B performs destination NAT, translating the public IP to the server's private IP. Combined with firewall policies in VDOM-B (allowing incoming traffic to the VIP) and VDOM-A (allowing traffic from the VDOM link to the server), this enables access. The VDOM link carries the translated traffic between VDOMs.

  • ✗

    Enable NAT on the VDOM link interface in VDOM-B and create a static route in VDOM-A pointing to the server.

    Why it's wrong here

    Enabling NAT on the VDOM link would translate the source IP, not the destination. For inbound access, destination NAT is required. Also, a static route in VDOM-A to the server is unnecessary because the server is directly connected. This option misapplies NAT direction and adds an irrelevant route.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.