Commands to Check Which Firewall Policy Matches Traffic
A FortiGate administrator is troubleshooting why traffic from a specific host (10.0.1.100) to a web server (203.0.113.50) is being denied. The administrator has confirmed that a firewall policy exists that should allow the traffic. Which TWO diagnostic commands would help identify the issue?
⚠ Common exam trap
Test-takers frequently confuse packet sniffing (which shows raw traffic) with flow debugging (which shows the firewall's internal decision process), leading them to choose 'diagnose sniffer packet' instead of 'diagnose debug flow' for identifying policy-based denials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose firewall policy list
'diagnose firewall policy list' displays the effective policy table, including policy IDs, match criteria, and action (accept/deny). This helps verify whether the policy intended for the traffic is actually present and in the correct order. Option C is correct because 'diagnose debug flow' enables real-time packet flow tracing, showing exactly which policy is matched (or not) and why the traffic is denied, such as a policy hit with action 'deny' or a session table lookup failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
get system performance status
Why it's wrong here
The `get system performance status` command reports live system metrics such as CPU usage, memory consumption, and concurrent session counts, which are useful for spotting resource exhaustion. However, it does not expose the firewall policy table or the internal decision-making process for a given source-to-destination flow, so it cannot reveal why a packet from 10.0.1.100 to 203.0.113.50 is being denied by policy. It is a health-check tool, not a policy-matching diagnostic.
- ✓
diagnose firewall policy list
Why this is correct
Executing `diagnose firewall policy list` prints every firewall policy entry with its ID, sequence, source, destination, service, action, and status in the exact evaluation order. This lets an administrator verify that a policy allowing 10.0.1.100 to 203.0.113.50 actually exists, is enabled, and is not overshadowed by an earlier deny-all or more specific deny rule. Because FortiGate matches first-match, checking the ordered list is an essential step in confirming whether the configuration matches the expected permit.
- ✓
diagnose debug flow
Why this is correct
The `diagnose debug flow` command, when paired with `diagnose debug enable`, traces each packet as it traverses the firewall and reports the exact policy ID that was hit, along with any drop reasons such as policy denied, session helper failure, or application control action. This real-time output shows precisely which rule matched the traffic from 10.0.1.100 to 203.0.113.50 and why it was not permitted, making it the definitive tool for policy-denial troubleshooting. It effectively correlates the packet with the firewall's security decision.
- ✗
execute ping-options source 10.0.1.100
Why it's wrong here
`execute ping-options source 10.0.1.100` alters the source IP used in ICMP echo requests generated by the FortiGate's own ping utility, which is a connectivity test from the firewall itself, not a way to test transit traffic through the unit. It does not affect how the firewall polices packets originating from a PC on the internal network, nor does it provide visibility into policy matching. Thus, setting this option would not help determine why the traffic is denied by a firewall policy.
- ✗
diagnose sniffer packet any 'host 203.0.113.50' 4
Why it's wrong here
A packet sniffer (e.g., `diagnose sniffer packet any 'host 203.0.113.50' 4`) captures network packets on the specified interface and can confirm that traffic from 10.0.1.100 is reaching the FortiGate or leaving it, but it does not inspect the firewall policy engine's internal state. The sniffer output will not show which policy rule was matched or the specific drop reason; it only shows raw frames at the network layer. To learn the policy decision, one must use tools like `diagnose debug flow` or examine the policy list.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.