NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator is implementing a policy to allow outbound traffic from the internal network to the internet. The requirements are: (1) all traffic from internal users must be source NATed to the external interface IP, (2) traffic from a specific server must use a different public IP, (3) HTTP traffic must be shaped to 10 Mbps. Which THREE configuration elements should the administrator create? (Choose three.)
⚠ Common exam trap
Watch out — candidates often confuse VIP (destination NAT) with IP pool (source NAT), leading candidates to incorrectly select VIP for source IP translation requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A traffic shaper for HTTP traffic
A traffic shaper is required to enforce bandwidth limits on HTTP traffic. In FortiGate, traffic shaping policies allow you to define per-policy bandwidth constraints, such as capping HTTP traffic to 10 Mbps, by applying a shaper to the firewall policy that matches HTTP traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A traffic shaper for HTTP traffic
Why this is correct
Traffic shapers are used to control bandwidth usage and prioritize traffic. In this scenario, to allow HTTP traffic while ensuring it doesn't saturate the link, a traffic shaper can be applied to the firewall policy to guarantee or limit bandwidth for HTTP. It doesn't affect the destination or source IP translation; it's a QoS mechanism.
- ✗
A VIP for the server
Why it's wrong here
A Virtual IP (VIP) maps an external public IP to an internal server's private IP, performing destination NAT. This is used when you want to publish a server to the internet. But here, the requirement is likely for outbound or source NAT (hiding internal IPs) or allowing HTTP from a specific IP, not for inbound access. Using a VIP would alter the destination address, which is not needed for this policy.
- ✓
A firewall policy with NAT enabled and the IP pool referenced
Why this is correct
The firewall policy defines the traffic matching criteria (source, destination, service) and actions (allow/deny). To perform source NAT for outgoing HTTP traffic, enable NAT on the policy and reference an IP pool to use a specific public IP as the source address. This ensures the traffic leaves with the designated public IP, and combined with a traffic shaper, controls bandwidth.
- ✓
An IP Pool for the specific server's public IP
Why this is correct
An IP pool is a set of public IP addresses used for source NAT (SNAT). When the firewall policy has NAT enabled, you can reference an IP pool to override the default egress interface IP. Here, using the specific server's public IP as the pool ensures that the HTTP traffic from that server appears to originate from that IP address, which may be required for access control or identification.
- ✗
A policy-based routing rule for the server
Why it's wrong here
Policy-based routing (PBR) is used to steer traffic based on source/destination or other criteria, usually to influence the routing path or next-hop. It is not needed for NAT or traffic shaping; those functions are handled by the firewall policy and shaper. Adding a PBR rule for this scenario would unnecessarily complicate routing and could cause unexpected behavior, but it's not a required element.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.