Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate has a central SNAT policy that translates internal users to a single IP pool address. The admin wants specific traffic (e.g., from a particular subnet) to use a different IP pool. What is the correct approach?

⚠ Common exam trap

Candidates often confuse central SNAT with policy-based NAT or VIP, mistakenly thinking that VIPs can be used for source NAT or that PBNAT rules can be inserted into the central NAT table, when in fact central SNAT policies are a distinct feature with their own ordered list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new central SNAT policy with the specific subnet as source and place it above the existing policy

Central SNAT policies are evaluated in sequential order, and the first matching policy is applied. By creating a new policy with the specific subnet as the source and placing it above the existing policy, the FortiGate will match the more specific traffic first and use the different IP pool, while all other traffic continues to match the original policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a new central SNAT policy with the specific subnet as source and place it above the existing policy

    Why this is correct

    Central SNAT policies are evaluated in strict top-down order, and the first policy whose source, destination, and service criteria match the traffic is applied. By creating a new policy with a more specific source subnet (e.g., 10.1.1.0/24) and placing it above the existing broader policy, you guarantee that traffic from that subnet is translated according to the new policy, while all other traffic falls through to the original policy below. This is the standard way to implement selective source translation when central NAT is enabled.

  • ✗

    Create a policy-based NAT rule with the specific subnet and place it above the central SNAT policy

    Why it's wrong here

    When central NAT is enabled, the FortiGate explicitly ignores policy-based NAT (PBNAT) rules for SNAT, so a policy-based NAT rule would not be evaluated at all regardless of its position. The FortiGate automatically disables or bypasses PBNAT SNAT rules in favor of central SNAT policies, meaning your specific subnet would not receive the desired translation. To achieve selective SNAT in a central NAT environment, you must use central SNAT policies, not PBNAT rules.

  • ✗

    Use VIP to translate the source address

    Why it's wrong here

    A Virtual IP (VIP) is designed for destination NAT (DNAT), translating the destination address of incoming traffic to an internal server, not the source address of outgoing traffic. Central SNAT policies translate the source IP of traffic as it egresses an interface, so a VIP does not alter the source address and cannot perform source address translation for your specific subnet. Applying a VIP would change where traffic goes, not where it appears to come from, which is exactly the opposite of the requirement.

  • ✗

    Modify the existing central SNAT policy to use a dynamic IP pool

    Why it's wrong here

    A dynamic IP pool merely changes how the existing central SNAT policy allocates translated source addresses—from a fixed address to a range—but it does not narrow or modify the source match criteria. The existing policy still matches its original broad source subnet, so it would continue to translate all traffic from that entire range, including your specific subnet, with the same behavior. To translate only a specific subnet differently, you must add a separate, more specific central SNAT policy above the existing one; swapping in a dynamic pool does not provide selective matching.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.