NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator needs to ensure that traffic from the LAN (192.168.1.0/24) to the DMZ (10.0.0.0/24) uses a specific outbound interface (port3) instead of the default route. Which feature should be configured to achieve this?
⚠ Common exam trap
Many exam-takers confuse policy-based routing (PBR) with static routes or SD-WAN, assuming that a static route with a higher administrative distance can override the default route for specific source-destination pairs, but static routes are destination-based and cannot match on source IP or other L4 criteria without PBR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy-based routing (PBR) in the firewall policy
Policy-based routing (PBR) allows the FortiGate to override the routing table for specific traffic based on criteria defined in a firewall policy, such as source and destination addresses. By configuring a PBR rule that matches traffic from 192.168.1.0/24 to 10.0.0.0/24 and setting the outbound interface to port3, the administrator can force this traffic to use port3 instead of the default route. This is the correct feature for interface-based path selection that is not based on destination prefix alone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Static route with a higher distance
Why it's wrong here
A static route with a higher administrative distance only affects route preference for destination-based lookups, making it less preferred than an existing route to the same prefix. Because it still matches only the destination network, it cannot select traffic based on source address, user, or application, so it cannot force specific internal clients to exit through port3.
- ✗
Virtual IP (VIP) with port forwarding
Why it's wrong here
A Virtual IP (VIP) with port forwarding performs destination NAT, translating the destination IP and port of inbound packets before routing. It applies only to sessions aimed at a published server and does not dictate the egress interface for outbound traffic originating from a source network, so it cannot steer that traffic out port3.
- ✓
Policy-based routing (PBR) in the firewall policy
Why this is correct
Policy-based routing (PBR) in a firewall policy matches traffic using firewall-level criteria such as source address, destination address, user, or application, and then overrides the routing table by defining a specific next-hop gateway and egress interface. This lets the administrator force selected internal traffic out port3 while all other traffic continues to use the normal destination-based routing table.
- ✗
SD-WAN rule to force traffic to port3
Why it's wrong here
SD-WAN rules only steer traffic when the egress interfaces are members of an SD-WAN zone and the firewall policy has SD-WAN enabled; otherwise, the rule is ignored. Here port3 is not described as part of an SD-WAN zone, so an SD-WAN rule cannot force traffic to that interface unless the administrator first adds port3 to an SD-WAN zone and references the rule in the policy.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.