NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to allow a server in VDOM-A to be accessed from the internet through VDOM-B, which has the public IP address. The administrator has already created a VDOM link between VDOM-A and VDOM-B. Which additional configuration is required to make the server accessible?
⚠ Common exam trap
The trap here is assuming that inter-VDOM routing and firewall policies alone are sufficient, overlooking the need for destination NAT via a VIP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a VIP on VDOM-B that maps the public IP to the server's private IP, and ensure firewall policies allow the traffic in both VDOMs.
To allow external access to a server behind a FortiGate with multiple VDOMs, a VIP must be configured on the VDOM with the public IP to perform destination NAT. Firewall policies in both VDOMs must permit the traffic, and the VDOM link carries the translated packets. Without the VIP, the server would not receive the traffic correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a firewall policy in VDOM-B that allows incoming traffic to the VDOM link interface and a policy in VDOM-A that allows traffic from the VDOM link to the server.
Why it's wrong here
While policies are necessary, they alone do not translate the public IP to the server's private IP. The traffic must also be NATed. Without destination NAT on VDOM-B, the server would receive packets with the public IP as destination and likely drop them. This option omits the essential NAT configuration.
- ✗
Create a central SNAT policy in VDOM-B to translate the public IP to the server's private IP, and apply it to the VDOM link.
Why it's wrong here
Central SNAT is used for source NAT, not destination NAT. Translating the public IP to the server's private IP is a destination NAT operation, which requires a VIP. Central SNAT would change the source address of outbound traffic, not enable inbound access to an internal server.
- ✓
Configure a VIP on VDOM-B that maps the public IP to the server's private IP, and ensure firewall policies allow the traffic in both VDOMs.
Why this is correct
A VIP (Virtual IP) on VDOM-B performs destination NAT, translating the public IP to the server's private IP. Combined with firewall policies in VDOM-B (allowing incoming traffic to the VIP) and VDOM-A (allowing traffic from the VDOM link to the server), this enables access. The VDOM link carries the translated traffic between VDOMs.
- ✗
Enable NAT on the VDOM link interface in VDOM-B and create a static route in VDOM-A pointing to the server.
Why it's wrong here
Enabling NAT on the VDOM link would translate the source IP, not the destination. For inbound access, destination NAT is required. Also, a static route in VDOM-A to the server is unnecessary because the server is directly connected. This option misapplies NAT direction and adds an irrelevant route.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.