NSE7 Enterprise Firewall and VDOMs Practice Question
In a multi-VDOM deployment, an administrator needs to route traffic between VDOM-A and VDOM-B. The administrator creates a VDOM link between the two VDOMs. What additional configuration is required on each VDOM to enable inter-VDOM traffic?
⚠ Common exam trap
Test-takers frequently assume a VDOM link alone provides full connectivity, forgetting that FortiOS requires explicit routing and firewall policies on both sides of the link to actually forward traffic between VDOMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a static route on each VDOM pointing to the other VDOM's networks via the VDOM link, and create a firewall policy allowing traffic
Inter-VDOM traffic via a VDOM link requires both a static route on each VDOM pointing to the remote VDOM's networks through the VDOM link interface, and a firewall policy on each VDOM that permits the desired traffic. Without the static route, the VDOM does not know how to reach the other VDOM's subnets; without the firewall policy, traffic is blocked by the implicit deny rule. The VDOM link itself provides the Layer 2 or Layer 3 connectivity between the VDOMs, but routing and policy enforcement are mandatory for traffic to flow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only a firewall policy on VDOM-A allowing traffic to VDOM-B
Why it's wrong here
A policy on VDOM-A alone permits only one direction; return traffic from VDOM-B is dropped. It tempts because a single policy appears sufficient, but inter-VDOM traffic requires policies on both VDOMs plus IP addresses on the VDOM link interfaces.
- ✗
Assign the VDOM link interfaces to the same VDOM
Why it's wrong here
Assigning both link interfaces to one VDOM defeats the purpose: a vdom-link's two ends must sit in different VDOMs to carry traffic between them. It is tempting because interfaces normally belong to a VDOM, but here each end must be placed in its own VDOM, then IP addresses and firewall policies added.
- ✗
Enable 'inter-vdom-routing' under system settings only
Why it's wrong here
Enabling inter-vdom-routing alone does nothing; the VDOM link interfaces still need IP addresses and firewall policies permitting traffic. It tempts because the setting name matches the goal, but the concrete requirement is addressing each link endpoint and adding policies on both VDOMs.
- ✓
Configure a static route on each VDOM pointing to the other VDOM's networks via the VDOM link, and create a firewall policy allowing traffic
Why this is correct
A VDOM link only provides the physical/logical path between VDOMs; each VDOM still needs a static route directing the peer's subnets out the link interface, plus a firewall policy permitting that inter-VDOM traffic, since FortiGate evaluates policies per VDOM.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.