NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator has configured a firewall policy with source NAT using an IP pool that contains two IP addresses: 203.0.113.10 and 203.0.113.11. The pool type is set to 'Overload'. The administrator notices that some outbound connections are failing, and when checking the session table, sees that many sessions are using the same source IP and port. What is the most likely cause of the connection failures?
⚠ Common exam trap
The trap here is assuming that an 'Overload' IP pool with multiple IPs will automatically distribute sessions evenly, when in fact it uses one IP until ports are exhausted before moving to the next.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate is running out of available source ports because too many sessions are being translated to the same IP address.
An 'Overload' IP pool allows multiple sessions to share the same IP address by using different source ports. However, each IP address has a finite number of ports (about 64,000). If the number of concurrent sessions exceeds this limit, new connections will fail because no ports are available. The solution is to add more IP addresses to the pool or use a different NAT configuration. This is a common issue in environments with high session counts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IP pool is configured with the wrong netmask, causing the FortiGate to incorrectly calculate the available addresses.
Why it's wrong here
The netmask of an IP pool is used to determine the range of addresses if the pool is a subnet, but in this case, the pool explicitly lists two IP addresses. The netmask does not affect the port allocation. A wrong netmask would cause the FortiGate to use incorrect IPs, but the symptom described is port exhaustion, not incorrect IP usage. This is not the most likely cause.
- ✓
The FortiGate is running out of available source ports because too many sessions are being translated to the same IP address.
Why this is correct
This is correct because with an 'Overload' IP pool, multiple sessions can be mapped to the same IP address, but each session requires a unique source port. The FortiGate has a limited number of ports per IP (approximately 64,000). If the number of concurrent sessions exceeds the available ports, new connections will fail. The administrator should consider adding more IP addresses to the pool or using a different NAT type.
- ✗
The IP pool is configured as 'Overload', which only allows one IP address to be used; the second IP is ignored.
Why it's wrong here
This is incorrect because an 'Overload' IP pool can contain multiple IP addresses and will use them all. Overload means that multiple sessions can share the same IP address, using different source ports. The second IP is not ignored; it will be used when the first reaches its port limit. The issue is not that only one IP is used.
- ✗
The firewall policy is using the wrong outgoing interface, so the NAT pool is not being applied correctly.
Why it's wrong here
If the wrong outgoing interface were used, the NAT pool might not be applied at all, or traffic might be routed incorrectly. However, the symptom of sessions using the same source IP and port suggests that NAT is working but ports are exhausted. The outgoing interface is likely correct because NAT is occurring. This option does not explain the port exhaustion issue.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.