Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator has a FortiGate with VDOMs 'VDOM-A' and 'VDOM-B' connected by an inter-VDOM link. Users in VDOM-A can reach a web server in VDOM-B, but return traffic from the server to clients is being dropped. The administrator has already created policies in both directions. Which action should the administrator take to resolve the dropped return traffic?

⚠ Common exam trap

The trap here is focusing on policies and NAT when the real cause is a missing return route in the second VDOM, since inter-VDOM links need routing configured independently on each side.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a static route in VDOM-B that points the client subnet to the inter-VDOM link interface as next-hop

Inter-VDOM links require routing in both directions. Even with policies in both VDOMs, VDOM-B must have a route for the client subnet pointing to the inter-VDOM link interface so the server's replies can return. Missing that route is the classic cause of one-way inter-VDOM traffic, and adding it restores bidirectional communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable asymmetric routing on both VDOMs with 'config system settings' and 'set asymmetric-route enable'

    Why it's wrong here

    Asymmetric routing handling allows a FortiGate to accept return packets that arrive on a different interface than the one used for the original session, but it is not the fix for inter-VDOM link return traffic. Enabling it here does not address the missing route or policy requirement. While disabling session helpers can help with asymmetric flows, enabling asymmetric routing does not create the return path needed between VDOM-A and VDOM-B.

  • ✓

    Add a static route in VDOM-B that points the client subnet to the inter-VDOM link interface as next-hop

    Why this is correct

    For return traffic to leave VDOM-B toward clients in VDOM-A, VDOM-B needs a route for the client subnet whose next-hop is the inter-VDOM link interface. Without that route, the server's replies have no path back and are dropped. Policies in both directions are necessary but not sufficient; routing must also exist in each VDOM, and this step supplies the missing route in VDOM-B.

  • ✗

    Increase the TCP session timeout in VDOM-B so return packets are not aged out before arrival

    Why it's wrong here

    Session timeouts affect how long idle sessions remain in the session table, not whether return packets have a valid path. The server's replies are dropped because VDOM-B lacks a route to the client subnet, so lengthening timeouts would not help. Adjusting timeouts is a tuning action, not a routing correction, and would leave the underlying reachability problem in place.

  • ✗

    Configure a firewall policy in VDOM-B with NAT enabled to translate the server address to the inter-VDOM link address

    Why it's wrong here

    Applying NAT on the VDOM-B policy would hide the real server address and is unnecessary for inter-VDOM routing. It could even break client expectations and does not solve the routing problem, since replies still need a route to the client subnet. The dropped traffic is caused by a missing return route, not by an address translation issue between the VDOMs.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.