NSE7 Enterprise Firewall and VDOMs Practice Question
Exhibit
Refer to the exhibit.
config vdom
edit "VDOM1"
config system interface
edit "port1"
set vdom "VDOM1"
set ip 192.168.1.1 255.255.255.0
set allowaccess ping https
next
end
config router static
edit 1
set device "port1"
set gateway 192.168.1.254
next
end
end
config vdom
edit "VDOM2"
config system interface
edit "port2"
set vdom "VDOM2"
set ip 10.10.10.1 255.255.255.0
set allowaccess ping
next
end
config router static
edit 1
set device "port2"
set gateway 10.10.10.254
next
end
endAn administrator configures two VDOMs as shown in the exhibit. They create an inter-VDOM link between VDOM1 and VDOM2. They then add a firewall policy in VDOM1 allowing traffic from port1 to the inter-VDOM link, and a policy in VDOM2 allowing traffic from the inter-VDOM link to port2. However, traffic from 192.168.1.10 to 10.10.10.50 fails. What is the most likely cause?
⚠ Common exam trap
Many candidates assume firewall policies alone control inter-VDOM traffic, overlooking that routing is a prerequisite for forwarding packets across the inter-VDOM link.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Missing route in VDOM1 for the 10.10.10.0/24 network
Inter-VDOM link traffic requires routing in both VDOMs. Even with correct firewall policies, VDOM1 must have a route to the destination network (10.10.10.0/24) pointing to the inter-VDOM link interface. Without this route, VDOM1 drops the packet before it can be forwarded across the link, causing the failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall policies are not correctly configured
Why it's wrong here
Inter-VDOM link traffic also requires a policy permitting the return path, and both VDOMs must route correctly; a one-way policy pair alone leaves replies dropped. Policies are tempting because they are the usual suspect, and they would be the cause if traffic passed one direction only.
- ✗
The inter-VDOM link is not configured
Why it's wrong here
An unconfigured inter-VDOM link would prevent the policies from referencing it, but the stem states the link was created and both policies added. It is tempting because missing link configuration is a frequent cause, and it would be correct if the link had never been defined.
- ✓
Missing route in VDOM1 for the 10.10.10.0/24 network
Why this is correct
FortiGate VDOMs maintain separate routing tables. VDOM1 needs a route pointing 10.10.10.0/24 out the inter-VDOM link interface; without it, return traffic to 192.168.1.10 cannot be forwarded, so the session fails despite both firewall policies permitting it.
- ✗
The allowaccess setting on port2 does not include ping
Why it's wrong here
allowaccess controls management access protocols on the interface, not forwarding of user traffic, so ping exclusion cannot block this session. It is tempting because allowaccess is a common oversight, and it would be correct if the administrator could not ping port2 itself.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.