Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator needs to allow inbound SSH access from the internet to a single internal server at IP 10.0.1.10. The public IP on the WAN interface is 203.0.113.5. Which type of object should be configured to map the public IP and port to the internal server?

⚠ Common exam trap

Candidates often confuse IP Pools (used for source NAT) with Virtual IPs (used for destination NAT), leading them to select Option A when the question clearly requires inbound mapping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Virtual IP (VIP)

A Virtual IP (VIP) object is the correct choice because it specifically maps a public IP and port (203.0.113.5:22) to a private IP and port (10.0.1.10:22) for inbound destination NAT (DNAT). This allows external SSH traffic to reach the internal server by translating the destination address and port at the FortiGate WAN interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IP Pool

    Why it's wrong here

    An IP pool in FortiOS provides a range of translated source IP addresses for outbound (source) NAT when traffic leaves an interface. It replaces the source address of a session so that return traffic can be routed back correctly, but it does not create any mapping for an inbound public destination IP to an internal server. Therefore, an IP pool cannot make an internal SSH server reachable from the internet; that requires a destination NAT mechanism such as a Virtual IP.

  • ✗

    Central NAT policy

    Why it's wrong here

    Central NAT policies are a separate policy table used to control whether and how NAT is applied, but they do not contain the actual address translation mappings for inbound traffic. To define a destination NAT rule, you must first create a Virtual IP (VIP) that maps the external IP and port to the internal SSH server, and then reference that VIP in a firewall policy or central NAT policy as the destination. A central NAT policy alone cannot translate an inbound SSH connection because the VIP object is what holds the public-to-private mapping.

  • ✓

    Virtual IP (VIP)

    Why this is correct

    A Virtual IP (VIP) is the FortiOS object that enables destination NAT and port forwarding for inbound traffic, which is exactly what is needed to allow SSH from the internet to an internal server. The administrator defines a VIP entry with the public interface IP and TCP port 22, maps it to the internal server's private IP and port 22, and then uses that VIP as the destination in a firewall policy that permits tcp/22. When a packet arrives for the public IP, the FortiGate rewrites the destination address to the internal IP, allowing the session to reach the SSH daemon.

  • ✗

    Address object

    Why it's wrong here

    An address object represents a single IP address, subnet, or fully qualified domain name and is used in firewall policies to match traffic, but it performs no translation. If you designate an address object for an internal SSH server and allow inbound traffic, the FortiGate still forwards packets with the original public destination IP, which does not exist inside the network, so the connection fails. Only a VIP can rewrite that destination address to the internal server's private IP; an address object simply helps match traffic for policy evaluation.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to allow SSH access from the internet to a server inside the network at 192.168.1.10. Which NAT configuration is needed?

easy
  • A.Use policy-based routing to forward SSH traffic
  • ✓ B.Create a VIP mapping public IP:22 to private IP:22 and an allow policy from WAN to DMZ
  • C.Configure source NAT on the outbound policy from DMZ to WAN
  • D.Enable NAT on the WAN interface

Why B: To allow inbound SSH access from the internet to an internal server, you need a Virtual IP (VIP) that maps a public IP and port (e.g., 203.0.113.5:22) to the private IP and port (192.168.1.10:22), combined with a firewall policy from the WAN zone to the DMZ zone that permits SSH traffic. This is Destination NAT (DNAT), which translates the destination address of incoming packets so they are routed to the internal server.

Variation 2. An administrator wants to allow access to an internal web server from the internet using a public IP address 203.0.113.10. The internal server has IP 10.0.0.5. Which FortiGate feature should be configured to translate the destination IP?

easy
  • ✓ A.Virtual IP (VIP)
  • B.Central SNAT
  • C.Policy-based routing
  • D.IP Pool

Why A: A Virtual IP (VIP) is the correct feature because it performs destination NAT (DNAT), translating the public destination IP 203.0.113.10 to the internal server IP 10.0.0.5. This allows inbound traffic from the internet to reach the internal web server by rewriting the destination IP address in the packet header as it traverses the FortiGate.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.