NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate is deployed with multiple VDOMs in NAT/route mode. The administrator has created a VDOM link between VDOM-1 and VDOM-2 and assigned IP addresses to both ends. A server in VDOM-1 (10.1.1.10/24) needs to reach a server in VDOM-2 (10.2.2.10/24). The administrator has added a static route in VDOM-1 for 10.2.2.0/24 pointing to the VDOM-2 link interface IP, and a static route in VDOM-2 for 10.1.1.0/24 pointing to the VDOM-1 link interface IP. However, traffic is not passing. Which additional configuration is required on the FortiGate to allow the traffic to flow?
⚠ Common exam trap
The trap here is assuming that adding routes and VDOM links automatically permits traffic between VDOMs, when in fact firewall policies are required in each VDOM to allow it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create firewall policies in VDOM-1 and VDOM-2 that allow traffic from the source subnet to the destination subnet on the respective VDOM link interfaces.
Inter-VDOM traffic is treated like traffic between two separate firewalls. Even with VDOM links and static routes in place, the implicit deny policy in each VDOM blocks the traffic. You must explicitly allow it with firewall policies in both VDOMs, specifying the source, destination, and VDOM link interface. No global setting or zone configuration can override this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable inter-VDOM routing globally using the command config system settings, set allow-inter-vdom-traffic enable.
Why it's wrong here
FortiGate does not have a global 'allow-inter-vdom-traffic' setting. Inter-VDOM traffic is permitted by default once VDOM links and routes are configured; no global toggle exists. This command is fabricated and would not resolve the issue. The problem is more likely missing firewall policies between the VDOMs.
- ✗
Assign the VDOM link interfaces to the same zone in both VDOMs to permit traffic between them.
Why it's wrong here
Zones are used within a VDOM to group interfaces for policy simplification. They do not enable inter-VDOM routing. Each VDOM has its own zones, and you cannot assign an interface to a zone in another VDOM. This configuration would not allow traffic to pass between VDOM-1 and VDOM-2.
- ✗
Configure a static route in the global routing table that points to both VDOMs, enabling inter-VDOM routing.
Why it's wrong here
The global routing table is only used for management traffic when a management VDOM is enabled, not for inter-VDOM data traffic. Inter-VDOM routing relies on per-VDOM routing tables and firewall policies. Adding a global route would not affect traffic between VDOM-1 and VDOM-2.
- ✓
Create firewall policies in VDOM-1 and VDOM-2 that allow traffic from the source subnet to the destination subnet on the respective VDOM link interfaces.
Why this is correct
By default, inter-VDOM traffic is blocked by implicit deny policies. You must create a policy in VDOM-1 allowing traffic from 10.1.1.0/24 to 10.2.2.0/24 with the outgoing interface as the VDOM link, and a reciprocal policy in VDOM-2. Without these, traffic is dropped even if routes exist.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.