Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate is configured with two VRF instances: VRF10 (for a customer) and VRF20 (for another customer). Each VRF has its own interfaces and routing table. The administrator wants to allow a specific server in VRF10 (10.10.10.5) to be reachable from a host in VRF20 (20.20.20.5) without leaking all routes between VRFs. Which FortiGate feature should be used to achieve this?

⚠ Common exam trap

The trap here is thinking that a firewall policy or a static route can directly bridge VRFs, when in fact you need a dedicated inter-VRF link with interfaces in each VRF.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An inter-VRF link using a pair of interfaces, one in each VRF, with a firewall policy allowing the specific traffic.

Inter-VRF routing on FortiGate is achieved by creating a link between VRFs using a pair of interfaces, each assigned to a different VRF. A firewall policy then controls what traffic can traverse that link. This allows selective reachability, such as permitting only one server, without leaking all routes between the VRFs. The other options either do not provide the necessary routing or lack the granular control required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A firewall policy with source VRF10 and destination VRF20, using NAT to translate the server IP.

    Why it's wrong here

    Firewall policies in FortiOS can match incoming and outgoing interfaces, but they do not directly match VRF instances. VRFs are separate routing domains; traffic between them requires a route. NAT could be used if a route exists, but without a route, the packet cannot be forwarded. Thus, a policy alone is insufficient; a route or inter-VRF mechanism is needed.

  • ✓

    An inter-VRF link using a pair of interfaces, one in each VRF, with a firewall policy allowing the specific traffic.

    Why this is correct

    FortiOS supports inter-VRF routing by creating a link between two VRF instances using a pair of interfaces (or subinterfaces) assigned to each VRF. A firewall policy then permits traffic from the source VRF to the destination VRF. This allows granular control: only the desired server can be reached if the policy restricts destination to 10.10.10.5. This method does not leak routes between VRFs, maintaining isolation.

  • ✗

    A static route in VRF20 pointing to 10.10.10.5/32 with the next-hop being the VRF10 interface gateway.

    Why it's wrong here

    A static route alone cannot cross VRF boundaries. The next-hop must be reachable within the same VRF. If you point to an interface in another VRF, the FortiGate will not resolve it because VRFs have separate routing tables. This would fail. Inter-VRF communication requires a dedicated link or route leaking with proper policies.

  • ✗

    Inter-VRF routing using a route leaking policy with a route-map.

    Why it's wrong here

    Route leaking in FortiOS typically involves static routes or BGP route leaking with route-maps, but it leaks entire prefixes or filtered sets. It does not provide per-host reachability without additional firewall policies. The requirement is to allow only one server, which is better handled by a firewall policy with NAT or by inter-VRF link. Route leaking would still require a policy to permit the traffic.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.