NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator is troubleshooting a connectivity issue where internal clients cannot reach a public web server. The administrator has confirmed that routing is correct and there are no security profiles blocking traffic. Which TWO debugging steps should the administrator take? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse configuration changes (like disabling security profiles or changing NAT mode) with actual debugging steps, when the correct approach is to first gather evidence using packet captures and policy verification before making any modifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a packet capture on the internal interface
Running a packet capture on the internal interface (Option B) allows the administrator to verify whether the client's request is actually reaching the FortiGate and whether the firewall is processing the traffic correctly. This step isolates whether the issue is before, at, or after the FortiGate, which is essential when routing is already confirmed as correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the FortiGate
Why it's wrong here
Rebooting the FortiGate only clears volatile runtime state such as the session table, ARP cache, and temporary buffers; it does not change persistent configuration errors like a missing route, misconfigured interface, or incorrect policy. Since the issue is a connectivity problem, a reboot is a blunt action that wastes time and may cause unnecessary downtime. This is not a diagnostic step because it neither isolates the fault nor provides information about the cause.
- ✓
Run a packet capture on the internal interface
Why this is correct
Running a packet capture on the internal interface is the correct first step because it tells you whether the client's frames actually reach the FortiGate. If the capture shows the traffic, then the problem lies in the FortiGate's processing (policy, route, NAT, or security profiles); if no traffic appears, the fault is upstream on the switch or the client. The capture also reveals the exact source/destination IPs, ports, and VLAN tags, which you then use to search for a matching firewall policy.
- ✗
Change the NAT mode to Central SNAT
Why it's wrong here
Changing the NAT mode to Central SNAT is a configuration change, not a troubleshooting step, and it can immediately affect active sessions and existing NAT rules. Even if the current NAT mode is policy-based, the correct move is to inspect the NAT policy list or run `diag debug` to verify translation behavior, not to switch modes blindly. Doing so before confirming connectivity with a packet capture can actually obscure the root cause.
- ✗
Disable the antivirus profile
Why it's wrong here
Since the scenario already confirms that no security profiles are blocking traffic, disabling the antivirus profile will have zero effect on connectivity. Moreover, turning off AV protection is a counterproductive shortcut that weakens the security posture while providing no diagnostic value. The failure is likely at a lower layer of the traffic path, such as policy matching or routing, not a UTM inspection issue.
- ✓
Check the firewall policy list for matching policies
Why this is correct
Checking the firewall policy list is an essential validation that a matching permit policy actually exists. The FortiGate applies implicit deny if no policy matches the traffic's source, destination, service, and interface, so a missing policy alone explains the connectivity failure. You should also verify the policy is enabled, not disabled or expired, and review the policy order because only the first matching policy is evaluated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.