Courseiva
Firewall Policies and NAT →mediumMultiple Select

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator is configuring a firewall policy to allow inbound HTTPS traffic from the internet to an internal web server. The web server has a private IP address 10.0.0.10. The administrator wants to translate the destination IP to the internal server using a Virtual IP (VIP). Which TWO of the following must be configured for the VIP to work correctly? (Choose two.)

⚠ Common exam trap

Many candidates think port forwarding must be explicitly enabled for any port-based VIP, but FortiGate's VIP automatically performs port mapping without requiring the 'port forwarding' checkbox when the external and internal ports are the same.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VIP must have the external IP set to a public IP address assigned to the FortiGate's WAN interface

A Virtual IP (VIP) must map a public IP address (typically assigned to the FortiGate's WAN interface) to the internal private IP of the web server. Without setting the external IP to a public address, the VIP cannot receive inbound traffic from the internet. Option D is correct because the firewall policy must reference the VIP as the destination address object; this triggers the destination NAT translation from the public IP to the private IP 10.0.0.10.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An IP Pool must be configured for the web server's return traffic

    Why it's wrong here

    An IP pool is used for source NAT, typically on outbound policies to translate private source addresses to public ones. Inbound DNAT via a VIP does not require an IP pool because the FortiGate's session table already tracks the reverse path for return traffic, automatically un-NATting packets back to the original client. Adding an IP pool here would only interfere with that stateful handoff.

  • ✗

    The VIP must have port forwarding enabled with the external and internal ports set to 443

    Why it's wrong here

    Port forwarding in a VIP is only necessary when you need to map an external port to a different internal port, such as publishing HTTPS on port 8443 while receiving traffic on 443. If the external and internal ports are identical, the VIP functions correctly without enabling port forwarding; the policy's service definition then determines which destination port is allowed. This is an optional parameter, not a prerequisite for basic VIP-based DNAT.

  • ✓

    The VIP must have the external IP set to a public IP address assigned to the FortiGate's WAN interface

    Why this is correct

    The external IP of a virtual IP must be one of the IP addresses assigned to the FortiGate's incoming interface, typically a public IP on the WAN. That address is the destination of the inbound packet, and only traffic addressed to the FortiGate itself can be intercepted and translated to the mapped internal server. If the external IP is not configured on the interface, the FortiGate has no way to receive that packet and the VIP cannot work.

  • ✓

    The firewall policy must use the VIP as the destination address object

    Why this is correct

    In a FortiGate policy, the destination address object must be set to the VIP object, not to the internal web server's real IP, for DNAT to be applied. The firewall evaluates the policy match against the pre-translation attributes, and using the VIP as the destination triggers the virtual IP translation. If you set the internal IP as the destination, the packet would be routed directly without any address translation and the VIP would be ignored.

  • ✗

    The firewall policy must have NAT enabled

    Why it's wrong here

    The 'NAT' checkbox in a firewall policy controls source NAT, which rewrites the source address of the packet. For inbound traffic handled by a VIP, destination NAT is already defined by the VIP object and occurs before the policy lookup, so the policy does not need to enable NAT. Enabling NAT on the policy here would unnecessarily translate the source address as well, which is not required for inbound web server access and may break return routing.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.