Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

In a multi-VDOM deployment, an administrator needs to route traffic between VDOM-A and VDOM-B. The administrator creates a VDOM link between the two VDOMs. What additional configuration is required on each VDOM to enable inter-VDOM traffic?

⚠ Common exam trap

Test-takers frequently assume a VDOM link alone provides full connectivity, forgetting that FortiOS requires explicit routing and firewall policies on both sides of the link to actually forward traffic between VDOMs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a static route on each VDOM pointing to the other VDOM's networks via the VDOM link, and create a firewall policy allowing traffic

Inter-VDOM traffic via a VDOM link requires both a static route on each VDOM pointing to the remote VDOM's networks through the VDOM link interface, and a firewall policy on each VDOM that permits the desired traffic. Without the static route, the VDOM does not know how to reach the other VDOM's subnets; without the firewall policy, traffic is blocked by the implicit deny rule. The VDOM link itself provides the Layer 2 or Layer 3 connectivity between the VDOMs, but routing and policy enforcement are mandatory for traffic to flow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only a firewall policy on VDOM-A allowing traffic to VDOM-B

    Why it's wrong here

    A policy on VDOM-A alone permits only one direction; return traffic from VDOM-B is dropped. It tempts because a single policy appears sufficient, but inter-VDOM traffic requires policies on both VDOMs plus IP addresses on the VDOM link interfaces.

  • ✗

    Assign the VDOM link interfaces to the same VDOM

    Why it's wrong here

    Assigning both link interfaces to one VDOM defeats the purpose: a vdom-link's two ends must sit in different VDOMs to carry traffic between them. It is tempting because interfaces normally belong to a VDOM, but here each end must be placed in its own VDOM, then IP addresses and firewall policies added.

  • ✗

    Enable 'inter-vdom-routing' under system settings only

    Why it's wrong here

    Enabling inter-vdom-routing alone does nothing; the VDOM link interfaces still need IP addresses and firewall policies permitting traffic. It tempts because the setting name matches the goal, but the concrete requirement is addressing each link endpoint and adding policies on both VDOMs.

  • ✓

    Configure a static route on each VDOM pointing to the other VDOM's networks via the VDOM link, and create a firewall policy allowing traffic

    Why this is correct

    A VDOM link only provides the physical/logical path between VDOMs; each VDOM still needs a static route directing the peer's subnets out the link interface, plus a firewall policy permitting that inter-VDOM traffic, since FortiGate evaluates policies per VDOM.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.