Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator needs to ensure that traffic from the LAN (192.168.1.0/24) to the DMZ (10.0.0.0/24) uses a specific outbound interface (port3) instead of the default route. Which feature should be configured to achieve this?

⚠ Common exam trap

Many exam-takers confuse policy-based routing (PBR) with static routes or SD-WAN, assuming that a static route with a higher administrative distance can override the default route for specific source-destination pairs, but static routes are destination-based and cannot match on source IP or other L4 criteria without PBR.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy-based routing (PBR) in the firewall policy

Policy-based routing (PBR) allows the FortiGate to override the routing table for specific traffic based on criteria defined in a firewall policy, such as source and destination addresses. By configuring a PBR rule that matches traffic from 192.168.1.0/24 to 10.0.0.0/24 and setting the outbound interface to port3, the administrator can force this traffic to use port3 instead of the default route. This is the correct feature for interface-based path selection that is not based on destination prefix alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Static route with a higher distance

    Why it's wrong here

    A static route with a higher administrative distance only affects route preference for destination-based lookups, making it less preferred than an existing route to the same prefix. Because it still matches only the destination network, it cannot select traffic based on source address, user, or application, so it cannot force specific internal clients to exit through port3.

  • ✗

    Virtual IP (VIP) with port forwarding

    Why it's wrong here

    A Virtual IP (VIP) with port forwarding performs destination NAT, translating the destination IP and port of inbound packets before routing. It applies only to sessions aimed at a published server and does not dictate the egress interface for outbound traffic originating from a source network, so it cannot steer that traffic out port3.

  • ✓

    Policy-based routing (PBR) in the firewall policy

    Why this is correct

    Policy-based routing (PBR) in a firewall policy matches traffic using firewall-level criteria such as source address, destination address, user, or application, and then overrides the routing table by defining a specific next-hop gateway and egress interface. This lets the administrator force selected internal traffic out port3 while all other traffic continues to use the normal destination-based routing table.

  • ✗

    SD-WAN rule to force traffic to port3

    Why it's wrong here

    SD-WAN rules only steer traffic when the egress interfaces are members of an SD-WAN zone and the firewall policy has SD-WAN enabled; otherwise, the rule is ignored. Here port3 is not described as part of an SD-WAN zone, so an SD-WAN rule cannot force traffic to that interface unless the administrator first adds port3 to an SD-WAN zone and references the rule in the policy.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.