nerdexam
Fortinet

NSE4 · Question #30

A FortiGate unit is configured with three Virtual Domains (VDOMs) as illustrated in the exhibit. Which of the following statements are true if the network administrator wants to route traffic…

The correct answer is A. The administrator can configure inter-VDOM links to avoid using external interfaces and routers. B. As with all FortiGate unit interfaces, firewall policies must be in place for traffic to be allowed to E. As each VDOM has an independent routing table, routing rules need to be set (for example, static. Inter-VDOM routing on a FortiGate utilizes virtual links for connectivity, requires explicit firewall policies for traffic flow, and necessitates proper routing table configurations within each VDOM due to their independent routing domains.

Submitted by carter_n· Apr 18, 2026VPN and Routing

Question

A FortiGate unit is configured with three Virtual Domains (VDOMs) as illustrated in the exhibit. Which of the following statements are true if the network administrator wants to route traffic between all the VDOMs? (Choose three.)

Exhibit

NSE4 question #30 exhibit

Options

  • AThe administrator can configure inter-VDOM links to avoid using external interfaces and routers.
  • BAs with all FortiGate unit interfaces, firewall policies must be in place for traffic to be allowed to
  • CThis configuration requires a router to be positioned between the FortiGate unit and the Internet
  • DInter-VDOM routing is automatically provided if all the subnets that need to be routed are locally
  • EAs each VDOM has an independent routing table, routing rules need to be set (for example, static

How the community answered

(62 responses)
  • A
    81% (50)
  • C
    8% (5)
  • D
    11% (7)

Why each option

Inter-VDOM routing on a FortiGate utilizes virtual links for connectivity, requires explicit firewall policies for traffic flow, and necessitates proper routing table configurations within each VDOM due to their independent routing domains.

AThe administrator can configure inter-VDOM links to avoid using external interfaces and routers.Correct

Inter-VDOM links are virtual interfaces configured on a FortiGate that allow traffic to be routed directly between VDOMs internally, eliminating the need for external physical interfaces and routers.

BAs with all FortiGate unit interfaces, firewall policies must be in place for traffic to be allowed toCorrect

Just like with physical interfaces, traffic flowing between VDOMs via inter-VDOM links requires explicit firewall policies to be configured between the respective inter-VDOM interfaces in each VDOM to permit the desired traffic.

CThis configuration requires a router to be positioned between the FortiGate unit and the Internet

Inter-VDOM routing is designed to route traffic *between VDOMs on the same FortiGate unit*, which specifically avoids the necessity of an external router for this purpose.

DInter-VDOM routing is automatically provided if all the subnets that need to be routed are locally

Inter-VDOM routing is not automatically provided; even if subnets are locally known, explicit configuration of inter-VDOM links and corresponding routing entries is required to enable communication between VDOMs.

EAs each VDOM has an independent routing table, routing rules need to be set (for example, staticCorrect

Each VDOM on a FortiGate maintains its own independent routing table; therefore, specific routing rules (e.g., static routes) must be configured in each VDOM to direct traffic towards the appropriate inter-VDOM link to reach subnets in other VDOMs.

Concept tested: FortiGate Inter-VDOM routing configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guides/894760/inter-vdom-links

Topics

#VDOMs#Inter-VDOM routing#Routing tables#Firewall policies

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice