NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate is configured with two VRF instances: VRF10 (for the finance department) and VRF20 (for the engineering department). Each VRF has its own routing table and interfaces. The administrator needs to allow a server in VRF10 (10.10.10.10) to communicate with a server in VRF20 (10.20.20.20). The administrator has already configured the necessary firewall policies to allow the traffic. However, pings from 10.10.10.10 to 10.20.20.20 fail. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that firewall policies alone can enable inter-VRF communication, overlooking the need for route leaking between isolated routing tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VRFs are isolated by default; inter-VRF routing requires configuring route leaking or a VRF-to-VRF link.
VRF instances provide isolated routing tables. By default, traffic cannot flow between them. To enable communication, the administrator must configure route leaking, which allows routes from one VRF to be imported into another. This is typically done using BGP with route targets or static route leaking commands. Firewall policies alone are insufficient because the FortiGate lacks a route to the destination network in the other VRF. Therefore, the missing configuration is route leaking or a VRF-to-VRF link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiGate requires a static route in the global routing table to route traffic between VRFs.
Why it's wrong here
The global routing table is separate from VRF routing tables. Adding a static route in the global table does not affect traffic within VRFs. Each VRF has its own routing table, and inter-VRF routing must be handled within those tables or via route leaking. A static route in the global table would not be consulted for traffic originating from an interface in a VRF. Therefore, this is not the correct solution.
- ✓
The VRFs are isolated by default; inter-VRF routing requires configuring route leaking or a VRF-to-VRF link.
Why this is correct
VRF instances on FortiGate are isolated routing domains. By default, there is no communication between them. To allow traffic between VRFs, the administrator must configure route leaking, which involves exporting routes from one VRF and importing them into another, typically using route-maps or BGP. Alternatively, a VRF-to-VRF link can be created using a pair of interfaces, but that is more complex. Since the administrator only configured firewall policies, the missing piece is the routing configuration to leak routes between VRF10 and VRF20.
- ✗
The FortiGate does not support inter-VRF routing; a separate physical interface is required to connect the VRFs.
Why it's wrong here
FortiGate supports inter-VRF routing through the use of VRF leaking or by using a shared interface. It is not true that a separate physical interface is required. Inter-VRF communication can be achieved by configuring route leaking between VRFs or by using a common interface that belongs to both VRFs (though an interface can only belong to one VRF). The most common method is route leaking, where specific routes are exported from one VRF and imported into another. The scenario does not mention route leaking, so that is likely the missing configuration.
- ✗
The firewall policies must be configured with the 'set vrf' option to specify the source and destination VRFs.
Why it's wrong here
Firewall policies in FortiGate do not have a 'set vrf' option. VRFs are associated with interfaces and routing tables, not directly with firewall policies. Firewall policies match on incoming and outgoing interfaces, which are already bound to VRFs. If the interfaces are correctly assigned to VRFs and policies allow traffic between them, the firewall is not the issue. The problem is likely routing between VRFs, as the FortiGate needs to know how to reach the destination network in the other VRF.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.