Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate is deployed in multi-VDOM mode. The administrator has created VDOM-A and VDOM-B, and configured an inter-VDOM link between them. Users in VDOM-A need to access a web server in VDOM-B. The administrator has added a static route in VDOM-A for the server's subnet pointing to the VDOM link interface, and a return route in VDOM-B. Which TWO additional configurations are required to allow the traffic? (Choose two.)

⚠ Common exam trap

The trap here is forgetting that each VDOM enforces its own firewall policies, so policies are needed on both sides of the VDOM link.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A firewall policy on VDOM-A that allows traffic from the internal interface to the VDOM link interface.

Inter-VDOM traffic requires firewall policies in both the originating and destination VDOMs. In VDOM-A, a policy must allow traffic from the internal interface to the VDOM link. In VDOM-B, a policy must allow traffic from the VDOM link to the server's interface. Routing must also be correct, but the scenario already includes static routes. NAT is not required unless specified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a central SNAT policy on VDOM-B to translate the destination IP addresses.

    Why it's wrong here

    Central SNAT is for source NAT, not destination NAT. Moreover, it is applied on the egress VDOM, not the ingress. In this scenario, the destination is the server in VDOM-B, and no destination translation is needed. The traffic should be routed and filtered, not NATed, unless there is a specific requirement not mentioned.

  • ✗

    Add a static route in VDOM-B for the user subnet pointing to the VDOM link interface.

    Why it's wrong here

    The scenario states that a return route in VDOM-B has already been configured. Therefore, adding another static route is redundant. The missing pieces are the firewall policies on both VDOMs. The return route ensures that replies can find their way back, but without policies, the traffic will be dropped.

  • ✓

    A firewall policy on VDOM-A that allows traffic from the internal interface to the VDOM link interface.

    Why this is correct

    Firewall policies are required in each VDOM to permit traffic. In VDOM-A, a policy must allow traffic from the user network to the VDOM link interface. Without this policy, the traffic will be dropped even if routing is correct. This is a fundamental requirement for inter-VDOM traffic, as each VDOM enforces its own security policies.

  • ✗

    Enable NAT on the VDOM link interface in VDOM-A to translate the source IP addresses.

    Why it's wrong here

    NAT is not required for inter-VDOM routing unless there is an overlapping subnet or a specific requirement to hide addresses. Enabling NAT on the VDOM link would translate source addresses, which might break return routing if not carefully configured. The question does not indicate a need for NAT; the primary requirements are firewall policies and correct routing.

  • ✓

    A firewall policy on VDOM-B that allows traffic from the VDOM link interface to the server's interface.

    Why this is correct

    Similarly, VDOM-B must have a firewall policy allowing traffic from the VDOM link interface to the server's network. Each VDOM acts as an independent firewall, so policies must be configured on both sides. Without this policy, the traffic will be blocked upon entering VDOM-B, even if it was allowed in VDOM-A.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.