NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator has enabled central NAT (policy-based NAT) in the VDOM. They need to translate all outbound traffic from the internal subnet 192.168.1.0/24 to the FortiGate's WAN interface IP when it leaves the network. Where must the NAT configuration be referenced in the firewall policy?
⚠ Common exam trap
The trap here is assuming that NAT must still be enabled in the firewall policy even when central NAT is enabled, which is not the case.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a central SNAT rule that matches the source subnet and outgoing interface, and ensure the firewall policy has no NAT configuration.
When central NAT is enabled, the FortiGate uses central SNAT rules instead of per-policy NAT. The firewall policy references the central SNAT rule implicitly by matching traffic; the policy itself must not have NAT enabled. The central SNAT rule defines the source and destination criteria and the translation. This separation simplifies management and avoids conflicting NAT configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable NAT in the firewall policy and select the central SNAT rule from the NAT dropdown.
Why it's wrong here
When central NAT is enabled, the firewall policy no longer has an 'Enable NAT' checkbox or a NAT dropdown to select a central rule. Instead, the policy simply references the central SNAT rule automatically based on matching criteria. Manually enabling NAT in the policy is not possible with central NAT and would not associate the central rule.
- ✗
Create an IP pool with the WAN IP and apply it as the NAT IP in the firewall policy, then disable central NAT.
Why it's wrong here
This describes the traditional policy-based NAT approach where NAT is configured per policy using an IP pool. However, the scenario explicitly states that central NAT is enabled. Central NAT and per-policy NAT are mutually exclusive; you cannot use an IP pool in the policy when central NAT is active. Disabling central NAT would contradict the requirement.
- ✗
Configure a virtual IP (VIP) for the internal subnet and reference it in the firewall policy as the source.
Why it's wrong here
A VIP is used for destination NAT (DNAT), typically to publish internal servers to the internet. Here the requirement is source NAT (SNAT) for outbound traffic from an internal subnet. Using a VIP as the source in a policy is not valid and would not achieve the required translation of internal source IPs to the WAN IP.
- ✓
Create a central SNAT rule that matches the source subnet and outgoing interface, and ensure the firewall policy has no NAT configuration.
Why this is correct
With central NAT enabled, SNAT is handled by central SNAT rules that are evaluated independently of firewall policies. The firewall policy itself must not have NAT enabled; it simply allows the traffic. The central SNAT rule matches source and destination criteria and performs the translation. This is the correct configuration for policy-based NAT in FortiOS.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.