Courseiva
Firewall Policies and NAT →mediumMultiple Select

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator needs to configure source NAT for a group of internal servers (10.0.1.100-10.0.1.110) so that each server uses a unique public IP from the range 203.0.113.20-203.0.113.30. The requirement is that each internal IP maps to a fixed external IP (one-to-one mapping) and not port overload. Which TWO settings should be configured in the IP Pool? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse 'One-to-One' with 'Overload' and select 'Type: Overload' thinking it still provides unique IPs, but Overload always uses PAT and cannot guarantee a fixed external IP per internal host.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External IP Range: 203.0.113.20-203.0.113.30

The External IP Range must be set to 203.0.113.20-203.0.113.30 to define the pool of public IPs that will be mapped one-to-one to the internal servers. Option D is correct because Type: One-to-One ensures each internal IP is permanently mapped to a unique external IP, without port address translation (PAT), meeting the requirement of fixed one-to-one mapping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Type: Overload

    Why it's wrong here

    Overload mode (Port Address Translation) maps many internal private addresses to a single external IP by multiplexing TCP/UDP sessions with unique source ports. While this conserves public addresses, it cannot provide each of the 11 internal servers with its own unique public-facing IP, so external devices cannot initiate direct, non-port-forwarded connections to individual servers. Therefore, Overload is not the correct type for this one-to-one requirement.

  • ✗

    Enable 'Fixed Port Range'

    Why it's wrong here

    The 'Fixed Port Range' option is an advanced setting available when an IP Pool is configured as Overload; it forces the FortiGate to use only the source ports you specify for translated sessions. This feature is designed for predictable port allocation or to integrate with destination-NAT rules, not to map internal IPs to external addresses. It does not change the core behavior of Overload, so it still cannot give each internal server a unique public IP, making it an incorrect choice for one-to-one source NAT.

  • ✓

    External IP Range: 203.0.113.20-203.0.113.30

    Why this is correct

    Specifying 'External IP Range: 203.0.113.20-203.0.113.30' defines a pool with exactly 11 usable public addresses (203.0.113.20, 21, ..., 30), matching the number of internal servers that must be translated. In one-to-one NAT, each inbound request to a given public IP is forwarded to the associated internal host alongside outbound sessions, preserving the port and eliminating port-exhaustion risk. This range is the correct external IP pool definition because its count precisely satisfies the stated requirement.

  • ✓

    Type: One-to-One

    Why this is correct

    Configuring 'Type: One-to-One' makes the FortiGate IP Pool perform static translation, where each internal IP is mapped to a distinct external IP without source-port rewriting. This mode is essential for servers that need to accept inbound connections directly (e.g., on TCP/25 or TCP/443), since the external IP maps back to the internal IP unchanged. With the appropriate external IP range, this setting is what actually gives each of the 11 internal servers its own unique publicly routable address.

  • ✗

    Use Central SNAT instead of IP Pool

    Why it's wrong here

    Central SNAT is an alternative NAT architecture in FortiOS that moves translation rules into a separate policy layer, and it does support one-to-one behavior via 'Match VIP' or subpools. However, the question explicitly asks for configuring source NAT through an IP Pool, so switching to Central SNAT would not answer the IP Pool inspection path. It also introduces additional policy complexity and is unnecessary when a straightforward IP Pool with Type: One-to-One and an external range already fulfills the requirement.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.