Courseiva
Advanced Networking and SD-WANmediumMultiple ChoiceObjective-mapped

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate is configured with multiple VRF instances. The administrator needs to ensure that traffic from VRF 10 can reach a server in VRF 20. Which configuration is required?

⚠ Common exam trap

Many exam-takers assume a firewall policy alone can enable inter-VRF communication, forgetting that routing must first be established between the VRFs via route leaking or static routes with VRF tags.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use static routes with the appropriate VRF tags to leak routes between VRFs

Inter-VRF route leaking in FortiGate is achieved by configuring static routes with the 'vrf' tag to specify the source VRF and using the 'dst-vrf' or 'vrf-leak' settings to export routes into the destination VRF. This allows traffic from VRF 10 to reach a server in VRF 20 by ensuring the necessary routes are present in both VRFs without merging the VRFs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable inter-VRF routing by setting 'vrf-leak enable' on the VRF instances

    Why it's wrong here

    No such command; route leaking is explicit.

  • Configure a firewall policy that allows traffic between the VRFs

    Why it's wrong here

    Firewall policies require routing first; they do not enable routing between VRFs.

  • Place both interfaces in the same VRF

    Why it's wrong here

    That would defeat the purpose of separate VRFs.

  • Use static routes with the appropriate VRF tags to leak routes between VRFs

    Why this is correct

    Route leaking can be done with static routes or redistribution.

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.