Courseiva
Firewall Policies and NAT →mediumMultiple Select

NSE4 Firewall Policies and NAT Practice Question

A company has two internet connections (WAN1 and WAN2). The administrator wants to route HTTP traffic from the internal network through WAN1, and all other traffic through WAN2. Which TWO configurations are needed?

⚠ Common exam trap

It's easy for candidates to confuse policy-based routing (Option D) with SD-WAN rules (Option A), not realizing that both are valid methods for application-based routing on FortiGate, and the question asks for TWO configurations needed, so both A and D are correct.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define an SD-WAN rule that matches HTTP and sets WAN1 as preferred

SD-WAN rules allow you to define application-based routing policies. By creating an SD-WAN rule that matches HTTP traffic and sets WAN1 as the preferred interface, the FortiGate will automatically steer HTTP sessions out through WAN1 while using the default routing table (which points to WAN2) for all other traffic. This leverages the SD-WAN feature's ability to perform per-application load balancing and failover without requiring policy-based routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Define an SD-WAN rule that matches HTTP and sets WAN1 as preferred

    Why this is correct

    An SD-WAN rule is the correct, centralized mechanism in FortiOS to steer traffic based on application or service. By creating a rule that matches HTTP and setting WAN1 as the preferred member, you explicitly route that protocol out of WAN1 while optionally maintaining failover to WAN2 if WAN1 goes down. This approach leverages SD-WAN health-check and load-balancing logic, making it the most robust and policy-driven solution.

  • ✗

    Apply NAT with IP pool on the firewall policy

    Why it's wrong here

    Applying NAT with an IP pool on the firewall policy only changes the source IP address used for outbound connections; it has no effect on the routing decision or which WAN interface is selected. The firewall policy determines whether traffic is allowed and how it is translated, but path selection is determined by the routing table or SD-WAN rules. Therefore, this would not cause HTTP traffic to prefer WAN1.

  • ✗

    Add a static route with a lower priority to WAN1

    Why it's wrong here

    Adding a static route with a lower priority (i.e., greater administrative distance) to WAN1 merely sets that route as a backup to a primary route, typically used only when the primary is unavailable. This is destination-based routing, not application-based, so it cannot selectively match HTTP traffic while ignoring other traffic to the same destination. It would not force HTTP specifically to use WAN1 under normal conditions, and may even be ignored if an overlapping static route with better priority exists.

  • ✓

    Create a policy-based routing rule to send HTTP traffic to WAN1

    Why this is correct

    Creating a policy-based routing (PBR) rule to send HTTP traffic to WAN1 is a valid alternative, as PBR can match protocol or service and set a statically defined next-hop interface. Unlike an SD-WAN rule, PBR does not automatically incorporate interface health-check or dynamic failover unless explicitly configured with additional rules. It works at the routing level before the routing table and is a fine choice, but SD-WAN is generally the more integrated and maintainable approach on FortiGate.

  • ✗

    Configure load balancing between WAN1 and WAN2

    Why it's wrong here

    Configuring load balancing between WAN1 and WAN2 distributes sessions across both links based on algorithms like spillover or volume, but it does not guarantee that HTTP traffic will specifically stay on WAN1. Load balancing may send some HTTP sessions to WAN2, especially if the algorithm is per-session or if the load on WAN1 is high. This lacks the policy-based, protocol-matching capability needed to make HTTP prefer WAN1 deterministically.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.