NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate is deployed in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator creates an inter-VDOM link named IVL1 with interface ivl-1-0 in VDOM-1 and ivl-1-1 in VDOM-2. Static routes are configured in both VDOMs to route traffic across the link. However, traffic from VDOM-1 to VDOM-2 is dropped. What is the most likely reason?
⚠ Common exam trap
The trap here is believing that inter-VDOM links bypass firewall policies or that routing alone is sufficient, when in fact policies are required in both VDOMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firewall policies allowing traffic from VDOM-1 to VDOM-2 across the inter-VDOM link have not been created in both VDOMs.
Inter-VDOM links provide a virtual connection between two VDOMs, but they are not exempt from firewall inspection. After creating the link and configuring static routes, you must add firewall policies in each VDOM to permit traffic from the source interface to the inter-VDOM link interface, and from the inter-VDOM link interface to the destination interface. Without these policies, the FortiGate drops the packets even though routing is correct. This is a common misconfiguration in multi-VDOM deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The inter-VDOM link pair must be in the same VDOM; splitting them across VDOMs disables the link.
Why it's wrong here
The entire purpose of an inter-VDOM link is to connect two different VDOMs. Each end of the link resides in a different VDOM. If both ends were in the same VDOM, it would not provide inter-VDOM connectivity. Splitting the pair across VDOMs is the correct configuration. The link is not disabled by this design; it is enabled. The traffic drop is caused by missing firewall policies that permit traffic across the link.
- ✗
The inter-VDOM link interfaces must be assigned to a zone before they can pass traffic.
Why it's wrong here
Inter-VDOM link interfaces do not require zone assignment. They can be referenced directly in firewall policies as source or destination interfaces. Zones are used to group multiple interfaces for policy simplification, but they are not a prerequisite for inter-VDOM link functionality. The traffic drop is due to missing policies, not a missing zone. Creating a zone would not resolve the issue unless policies are also added.
- ✓
Firewall policies allowing traffic from VDOM-1 to VDOM-2 across the inter-VDOM link have not been created in both VDOMs.
Why this is correct
Inter-VDOM link traffic is subject to firewall policies. Even with correct static routes, you must create a policy in VDOM-1 that allows traffic from the internal interface to ivl-1-0, and a policy in VDOM-2 that allows traffic from ivl-1-1 to the destination interface. Without these policies, the FortiGate drops the traffic. This is the most common oversight when configuring inter-VDOM routing. Both directions require policies because each VDOM inspects traffic independently.
- ✗
Inter-VDOM links do not support static routing; dynamic routing protocols must be used.
Why it's wrong here
Inter-VDOM links are treated like regular interfaces and fully support static routes. You can configure a static route in each VDOM pointing to the other VDOM's inter-VDOM link IP as the next-hop. Dynamic routing is optional, not mandatory. The drop is not due to a routing protocol limitation but likely due to missing firewall policies. Static routing over inter-VDOM links is a standard and supported configuration.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.