Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate is deployed in multi-VDOM mode with VDOM-1 and VDOM-2. The administrator creates an inter-VDOM link named IVL1 with interface ivl-1-0 in VDOM-1 and ivl-1-1 in VDOM-2. Static routes are configured in both VDOMs to route traffic across the link. However, traffic from VDOM-1 to VDOM-2 is dropped. What is the most likely reason?

⚠ Common exam trap

The trap here is believing that inter-VDOM links bypass firewall policies or that routing alone is sufficient, when in fact policies are required in both VDOMs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Firewall policies allowing traffic from VDOM-1 to VDOM-2 across the inter-VDOM link have not been created in both VDOMs.

Inter-VDOM links provide a virtual connection between two VDOMs, but they are not exempt from firewall inspection. After creating the link and configuring static routes, you must add firewall policies in each VDOM to permit traffic from the source interface to the inter-VDOM link interface, and from the inter-VDOM link interface to the destination interface. Without these policies, the FortiGate drops the packets even though routing is correct. This is a common misconfiguration in multi-VDOM deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The inter-VDOM link pair must be in the same VDOM; splitting them across VDOMs disables the link.

    Why it's wrong here

    The entire purpose of an inter-VDOM link is to connect two different VDOMs. Each end of the link resides in a different VDOM. If both ends were in the same VDOM, it would not provide inter-VDOM connectivity. Splitting the pair across VDOMs is the correct configuration. The link is not disabled by this design; it is enabled. The traffic drop is caused by missing firewall policies that permit traffic across the link.

  • ✗

    The inter-VDOM link interfaces must be assigned to a zone before they can pass traffic.

    Why it's wrong here

    Inter-VDOM link interfaces do not require zone assignment. They can be referenced directly in firewall policies as source or destination interfaces. Zones are used to group multiple interfaces for policy simplification, but they are not a prerequisite for inter-VDOM link functionality. The traffic drop is due to missing policies, not a missing zone. Creating a zone would not resolve the issue unless policies are also added.

  • ✓

    Firewall policies allowing traffic from VDOM-1 to VDOM-2 across the inter-VDOM link have not been created in both VDOMs.

    Why this is correct

    Inter-VDOM link traffic is subject to firewall policies. Even with correct static routes, you must create a policy in VDOM-1 that allows traffic from the internal interface to ivl-1-0, and a policy in VDOM-2 that allows traffic from ivl-1-1 to the destination interface. Without these policies, the FortiGate drops the traffic. This is the most common oversight when configuring inter-VDOM routing. Both directions require policies because each VDOM inspects traffic independently.

  • ✗

    Inter-VDOM links do not support static routing; dynamic routing protocols must be used.

    Why it's wrong here

    Inter-VDOM links are treated like regular interfaces and fully support static routes. You can configure a static route in each VDOM pointing to the other VDOM's inter-VDOM link IP as the next-hop. Dynamic routing is optional, not mandatory. The drop is not due to a routing protocol limitation but likely due to missing firewall policies. Static routing over inter-VDOM links is a standard and supported configuration.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.