Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator needs to allow SMTP traffic from the internal network to an external mail server. The internal network uses source NAT to the external interface IP. Which firewall policy configuration is correct?

⚠ Common exam trap

Many exam-takers confuse SMTP ports (25 vs 587) or assume SMTP can use UDP, but the exam tests the fundamental requirement that outbound internet traffic must have NAT enabled and that SMTP is TCP-based.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy: source internal, destination external, service SMTP, enable NAT

SMTP traffic from the internal network to an external mail server requires source NAT (masquerading) to translate private source IPs to the FortiGate's external interface IP. This ensures return traffic is routed back correctly. The default SMTP service uses TCP port 25, and enabling NAT on the policy is the standard configuration for outbound traffic to the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Policy: source internal, destination external, service SMTP, enable NAT

    Why this is correct

    Enable NAT on the policy so the FortiGate performs source NAT (hide/PAT), translating the internal source IP (e.g., 10.0.0.10) to the interface's public IP address. This makes the SMTP connection appear to originate from a routable public address, and the stateful session table ensures replies from the external mail server are returned to the correct internal host. Without this translation, the outbound SYN would carry a private source address that ISPs drop.

  • ✗

    Policy: source internal, destination external, service SMTP, disable NAT

    Why it's wrong here

    With NAT disabled, the FortiGate forwards packets unchanged, preserving the private source IP. The external mail server will send responses to that non-routable address, and return packets will be discarded by ISP routers because private addresses are not routed on the internet. Even if the mail server tried to respond, the internal host would never receive the SYN-ACK, so the TCP handshake fails; disabling NAT is only viable when clients already have public IPs.

  • ✗

    Policy: source internal, destination external, service SMTP (port 587), enable NAT

    Why it's wrong here

    The built-in SMTP service object in FortiOS corresponds to TCP port 25, which is the standard SMTP mail transfer port between mail servers. Port 587 is specifically for SMTP message submission, often requiring authentication, and is not the same as plain SMTP delivery. Choosing port 587 would not satisfy a requirement to allow "SMTP traffic" unless the administrator explicitly intends to permit only client submissions, which the question stem does not indicate.

  • ✗

    Policy: source internal, destination external, service SMTP (UDP), enable NAT

    Why it's wrong here

    SMTP is a TCP-based protocol because it requires reliable, ordered delivery of commands and message data; there is no standard UDP variant. Selecting a UDP service object incorrectly would allow the FortiGate to forward UDP datagrams to port 25, but real SMTP clients and servers will not communicate over UDP, so legitimate email delivery would still fail. Additionally, the FortiOS service object for SMTP is defined as TCP/25, not UDP.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.