Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate is configured with multiple VDOMs in NAT/route mode. The administrator wants to enable communication between VDOM-A and VDOM-B using an inter-VDOM link. The administrator creates the link and assigns IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. The administrator then adds a static route in VDOM-A to VDOM-B's network (192.168.2.0/24) via 10.0.0.2, and a static route in VDOM-B to VDOM-A's network (192.168.1.0/24) via 10.0.0.1. However, traffic still fails. What is the most likely missing configuration?

⚠ Common exam trap

The trap here is focusing on routing or interface settings when the actual missing component is the firewall policy, which is mandatory for inter-VDOM traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A firewall policy allowing traffic from VDOM-A to VDOM-B is missing.

Inter-VDOM routing requires both routing and firewall policies. The administrator has configured IP addresses and static routes, but traffic is still blocked because no firewall policy permits it. A policy must be added in each VDOM to allow traffic from the source network to the destination network via the inter-VDOM link interface. Once the policies are in place, communication will succeed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The static routes must be configured with the 'set gateway' parameter instead of 'set device'.

    Why it's wrong here

    Static routes on FortiGate use 'set gateway' to specify the next-hop IP address and 'set device' to specify the outgoing interface. In this scenario, the administrator likely configured the routes correctly with gateway 10.0.0.2 and device the inter-VDOM link interface. Using 'set device' alone without a gateway would be incorrect for a point-to-point link, but the scenario implies the routes are set. The missing element is the firewall policy.

  • ✓

    A firewall policy allowing traffic from VDOM-A to VDOM-B is missing.

    Why this is correct

    Even with correct IP addresses and routes, inter-VDOM traffic is blocked by default. A firewall policy must be configured in each VDOM to permit traffic from the source network to the destination network via the inter-VDOM link interface. Without this policy, the FortiGate drops the packets, causing communication to fail.

  • ✗

    The inter-VDOM link interfaces must have 'set allowaccess ping' enabled.

    Why it's wrong here

    The allowaccess setting controls administrative access to the interface, not transit traffic. Enabling ping on the interface would allow pinging the interface IP itself, but it does not permit traffic to pass through. The failure is due to missing firewall policies, not administrative access settings.

  • ✗

    The inter-VDOM link interfaces must be added to a zone in each VDOM.

    Why it's wrong here

    Adding the interfaces to a zone is not required for inter-VDOM routing. Zones are used to group interfaces for policy convenience, but they do not enable routing. The missing piece is likely a firewall policy, not zone membership. Zones would not resolve the traffic failure if policies are absent.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.