NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator wants VDOM-A and VDOM-B to exchange routing information dynamically without using static routes. The administrator has already created a VDOM link named 'vlink' between the two VDOMs and assigned IP addresses 10.0.0.1/30 and 10.0.0.2/30 to the respective interfaces. Which additional configuration is required on each VDOM to enable OSPF adjacency over the VDOM link?
⚠ Common exam trap
The trap here is assuming that creating a VDOM link automatically enables routing protocols or that a firewall policy is needed for OSPF, when in fact OSPF must be explicitly configured on the link interfaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable OSPF on the VDOM link interface and assign both interfaces to the same OSPF area.
To enable OSPF over a VDOM link, you must configure OSPF on the link interfaces and ensure they are in the same area. This allows the two VDOMs to form an adjacency and exchange routes dynamically. The VDOM link provides the Layer 3 connectivity, but the routing protocol configuration is what enables dynamic route exchange.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a firewall policy allowing OSPF (protocol 89) between the VDOM link interfaces.
Why it's wrong here
While firewall policies are needed for traffic between VDOMs, OSPF is a routing protocol and does not require a firewall policy for its own operation. Inter-VDOM link traffic for routing protocols is allowed by default when the link is properly configured. Adding a policy for OSPF is not required and does not enable the adjacency.
- ✗
Set the VDOM link interfaces to 'wan' role and enable OSPF on the physical interfaces.
Why it's wrong here
The VDOM link is a virtual interface, not a physical one. Assigning a 'wan' role is unnecessary and does not affect OSPF operation. OSPF should be enabled on the VDOM link interfaces themselves, not on unrelated physical interfaces. This option misdirects by referencing physical interfaces that are not part of the VDOM link.
- ✓
Enable OSPF on the VDOM link interface and assign both interfaces to the same OSPF area.
Why this is correct
OSPF requires that interfaces be enabled for OSPF and placed in the same area to form an adjacency. The VDOM link acts as a point-to-point connection, so configuring both ends with matching area ID and network type will allow OSPF neighbors to form. This is the standard method for dynamic routing between VDOMs.
- ✗
Configure a static route on each VDOM pointing to the other VDOM's interface IP address.
Why it's wrong here
Static routes do not enable dynamic routing protocol adjacencies. While static routes could provide reachability, they do not fulfill the requirement to exchange routing information dynamically. The question specifically asks for OSPF adjacency, which requires protocol configuration, not static routes.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.