NSE4 · Question #30
A FortiGate unit is configured with three Virtual Domains (VDOMs) as illustrated in the exhibit. Which of the following statements are true if the network administrator wants to route traffic…
The correct answer is A. The administrator can configure inter-VDOM links to avoid using external interfaces and routers. B. As with all FortiGate unit interfaces, firewall policies must be in place for traffic to be allowed to E. As each VDOM has an independent routing table, routing rules need to be set (for example, static. Inter-VDOM routing on a FortiGate utilizes virtual links for connectivity, requires explicit firewall policies for traffic flow, and necessitates proper routing table configurations within each VDOM due to their independent routing domains.
Question
A FortiGate unit is configured with three Virtual Domains (VDOMs) as illustrated in the exhibit. Which of the following statements are true if the network administrator wants to route traffic between all the VDOMs? (Choose three.)
Exhibit
Options
- AThe administrator can configure inter-VDOM links to avoid using external interfaces and routers.
- BAs with all FortiGate unit interfaces, firewall policies must be in place for traffic to be allowed to
- CThis configuration requires a router to be positioned between the FortiGate unit and the Internet
- DInter-VDOM routing is automatically provided if all the subnets that need to be routed are locally
- EAs each VDOM has an independent routing table, routing rules need to be set (for example, static
How the community answered
(62 responses)- A81% (50)
- C8% (5)
- D11% (7)
Why each option
Inter-VDOM routing on a FortiGate utilizes virtual links for connectivity, requires explicit firewall policies for traffic flow, and necessitates proper routing table configurations within each VDOM due to their independent routing domains.
Inter-VDOM links are virtual interfaces configured on a FortiGate that allow traffic to be routed directly between VDOMs internally, eliminating the need for external physical interfaces and routers.
Just like with physical interfaces, traffic flowing between VDOMs via inter-VDOM links requires explicit firewall policies to be configured between the respective inter-VDOM interfaces in each VDOM to permit the desired traffic.
Inter-VDOM routing is designed to route traffic *between VDOMs on the same FortiGate unit*, which specifically avoids the necessity of an external router for this purpose.
Inter-VDOM routing is not automatically provided; even if subnets are locally known, explicit configuration of inter-VDOM links and corresponding routing entries is required to enable communication between VDOMs.
Each VDOM on a FortiGate maintains its own independent routing table; therefore, specific routing rules (e.g., static routes) must be configured in each VDOM to direct traffic towards the appropriate inter-VDOM link to reach subnets in other VDOMs.
Concept tested: FortiGate Inter-VDOM routing configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guides/894760/inter-vdom-links
Topics
Community Discussion
No community discussion yet for this question.
