NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate is configured with multiple VRF instances. The administrator needs to ensure that traffic from VRF 10 can reach a server in VRF 20. Which configuration is required?
⚠ Common exam trap
Many exam-takers assume a firewall policy alone can enable inter-VRF communication, forgetting that routing must first be established between the VRFs via route leaking or static routes with VRF tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use static routes with the appropriate VRF tags to leak routes between VRFs
Inter-VRF route leaking in FortiGate is achieved by configuring static routes with the 'vrf' tag to specify the source VRF and using the 'dst-vrf' or 'vrf-leak' settings to export routes into the destination VRF. This allows traffic from VRF 10 to reach a server in VRF 20 by ensuring the necessary routes are present in both VRFs without merging the VRFs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable inter-VRF routing by setting 'vrf-leak enable' on the VRF instances
Why it's wrong here
No such command; route leaking is explicit.
- ✗
Configure a firewall policy that allows traffic between the VRFs
Why it's wrong here
Firewall policies require routing first; they do not enable routing between VRFs.
- ✗
Place both interfaces in the same VRF
Why it's wrong here
That would defeat the purpose of separate VRFs.
- ✓
Use static routes with the appropriate VRF tags to leak routes between VRFs
Why this is correct
Route leaking can be done with static routes or redistribution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.