NSE4 Firewall Policies and NAT Practice Question
A FortiGate admin configures an IP pool with type 'Fixed Port Range' to translate source IPs from 192.168.1.0/24 to 203.0.113.0/28 using port range 10000-20000. After applying the IP pool to a policy, some users cannot establish connections while others work. What is the MOST likely cause?
⚠ Common exam trap
Test-takers frequently confuse Fixed Port Range with Dynamic IP Pool (PAT), where overload allows many internal hosts to share a single external IP; candidates mistakenly think 'overload' is a setting in Fixed Port Range or that the port range itself is the bottleneck, rather than the number of external IPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP pool's port range is exhausted because the number of internal hosts exceeds the number of available port ranges
Fixed Port Range NAT uses a one-to-one mapping of source IPs to unique port ranges. With a /28 pool (16 IPs) and port range 10000-20000 (10,001 ports), each internal host gets a dedicated port block. If more than 16 concurrent internal hosts attempt NAT, the pool is exhausted, causing connection failures for excess hosts. This matches the symptom where some users work and others do not.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The internal subnet is using RFC 1918 addresses that cannot be NATed
Why it's wrong here
NAT (source NAT) is specifically designed to translate private RFC 1918 addresses into public addresses from an IP pool; these private addresses are not inherently non-NATable. The FortiGate maps each internal host's source IP to a public pool address, so using RFC 1918 internally is a standard scenario rather than a fault. The true failure here is not address incompatibility but the exhaustion of fixed port blocks assigned from the pool.
- ✓
The IP pool's port range is exhausted because the number of internal hosts exceeds the number of available port ranges
Why this is correct
With a fixed-port-range IP pool, the FortiGate reserves a dedicated block of source ports per internal host on the pool's IP address. If you have more internal hosts than available port blocks (e.g., 5,000 hosts with only 4,000 blocks), later hosts receive no port allocation and their sessions are denied. This is a capacity limit caused by the deterministic, non-dynamic port-block allocation of the fixed-range mode.
- ✗
The IP pool is configured with overload enabled, causing conflicts
Why it's wrong here
In FortiOS, the 'fixed port range' and 'overload' settings are mutually exclusive; a pool cannot be configured with both at once. If overload were enabled, the pool would act as a dynamic PAT pool, assigning ports on demand instead of reserving fixed blocks, so the symptom of exhausted port ranges would not occur. Therefore, an overload-enabled fixed pool is an impossible configuration and not the cause of the problem.
- ✗
The firewall policy has NAT disabled
Why it's wrong here
An IP pool is only invoked when the matching firewall policy has source NAT (SNAT) enabled. If NAT were disabled, the FortiGate would simply route traffic untranslated, and the configured IP pool would never be consulted — making the pool irrelevant to the observed failure. Since a fixed-port-range pool is clearly in use, the policy almost certainly has NAT enabled, so this option does not explain the connectivity issue.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.