NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate is configured with multiple VDOMs. The administrator wants to enable inter-VDOM routing between VDOM-A and VDOM-B. The administrator creates an inter-VDOM link and assigns IP addresses to both ends. Which additional configuration is required to allow traffic to pass between the VDOMs?
⚠ Common exam trap
The trap here is thinking that creating the inter-VDOM link and adding routes is enough, when in fact firewall policies in both VDOMs are also required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a firewall policy in VDOM-A allowing traffic from the source interface to the inter-VDOM link interface, and a policy in VDOM-B allowing traffic from the inter-VDOM link interface to the destination interface.
To enable inter-VDOM routing, you must create an inter-VDOM link and assign IP addresses. Then, you must add firewall policies in each VDOM to permit traffic across the link. Specifically, a policy in the source VDOM allowing traffic from the internal interface to the inter-VDOM link interface, and a policy in the destination VDOM allowing traffic from the inter-VDOM link interface to the destination interface. These policies are required because each VDOM inspects traffic independently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable inter-VDOM routing globally under System > Settings.
Why it's wrong here
There is no global setting called 'inter-VDOM routing' that must be enabled. Inter-VDOM routing is achieved by creating inter-VDOM links and configuring firewall policies. The FortiGate does not have a master switch to turn on inter-VDOM routing. The administrator must create the link and policies. Relying on a global setting would not work because no such setting exists. The correct approach is to define the link and policies explicitly.
- ✓
Create a firewall policy in VDOM-A allowing traffic from the source interface to the inter-VDOM link interface, and a policy in VDOM-B allowing traffic from the inter-VDOM link interface to the destination interface.
Why this is correct
Inter-VDOM link traffic is inspected by the firewall in each VDOM. Therefore, you need a policy in the source VDOM that permits traffic from the internal interface to the inter-VDOM link interface, and a policy in the destination VDOM that permits traffic from the inter-VDOM link interface to the destination interface. This two-policy requirement is mandatory. Without both policies, the FortiGate drops the traffic even if routing is correct. This is the standard configuration for inter-VDOM routing.
- ✗
Assign both inter-VDOM link interfaces to the same zone.
Why it's wrong here
Inter-VDOM link interfaces are in different VDOMs and cannot be assigned to the same zone because zones are per-VDOM objects. A zone is a group of interfaces within a single VDOM. Since each end of the inter-VDOM link resides in a different VDOM, they cannot share a zone. Even if they could, zone assignment does not replace the need for firewall policies. The traffic would still be dropped without policies allowing it.
- ✗
Configure a static route in each VDOM pointing to the inter-VDOM link, and enable 'allow inter-VDOM traffic' on the link.
Why it's wrong here
Static routes are necessary for routing, but they alone do not permit traffic; firewall policies are also required. The option also mentions an 'allow inter-VDOM traffic' setting on the link, which does not exist. Inter-VDOM links do not have such a toggle. The administrator must create firewall policies to allow traffic. Without policies, the traffic is dropped even with correct routes. The suggested setting is fictitious and would not resolve the issue.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.