Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

An administrator has configured a FortiGate with two VRF instances: VRF10 and VRF20. They need to allow a server in VRF10 (10.10.10.0/24) to communicate with a server in VRF20 (10.20.20.0/24). The administrator creates a firewall policy with source interface VRF10 and destination interface VRF20, but traffic is not passing. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that a firewall policy alone can enable inter-VRF traffic, overlooking the need for route leaking between separate routing tables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VRF instances are isolated by default; inter-VRF traffic requires a static route or policy route to leak routes between VRFs.

FortiGate VRF instances have separate routing tables. To allow traffic between them, the administrator must configure route leaking, typically by adding a static route in each VRF that points to the other VRF's interface or using policy routes. Without these routes, the FortiGate will drop packets even if a firewall policy permits them, because it cannot determine the next hop for the destination network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firewall policy must have 'match-vip' enabled to allow traffic between different VRFs.

    Why it's wrong here

    'match-vip' is used for matching VIPs in firewall policies and is unrelated to inter-VRF routing. Enabling it would not create the necessary routes between VRF10 and VRF20. The issue is the absence of route leaking, not VIP matching. This option confuses a feature for destination NAT with VRF routing requirements.

  • ✓

    VRF instances are isolated by default; inter-VRF traffic requires a static route or policy route to leak routes between VRFs.

    Why this is correct

    FortiGate VRF instances maintain separate routing tables. By default, there is no route leaking between VRFs. Even with a firewall policy allowing traffic, the FortiGate cannot forward packets from VRF10 to VRF20 without a route in each VRF pointing to the other. A static route or policy route must be configured to leak the destination prefix between the VRFs, enabling inter-VRF communication.

  • ✗

    Inter-VRF traffic is only supported when using VXLAN tunnels between the VRFs.

    Why it's wrong here

    VXLAN is not required for inter-VRF communication on a single FortiGate. While VXLAN can be used for overlay networks, basic inter-VRF routing can be achieved with static routes or policy routes that leak prefixes between VRF tables. Requiring VXLAN would be an unnecessary complexity and is not a default requirement.

  • ✗

    VRF instances require the use of 'set vrf' in the firewall policy to specify the source and destination VRFs.

    Why it's wrong here

    Firewall policies on FortiGate do not use a 'set vrf' command to specify VRFs. VRF assignment is done on interfaces, and policies reference interfaces. The policy already uses VRF10 and VRF20 interfaces, but without routes, traffic cannot be forwarded. The 'set vrf' option is not valid in this context.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.