Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate has a policy-based NAT rule that translates source IPs from subnet 192.168.1.0/24 to 203.0.113.10 when accessing the internet. The admin also enables Central SNAT with a rule that translates the same subnet to 203.0.113.20. If both are configured, which translation will be applied to traffic from 192.168.1.0/24 to the internet?

⚠ Common exam trap

A common mix-up: candidates assume Central SNAT, being a centralized feature, overrides all other NAT rules, but FortiGate explicitly gives policy-based NAT higher precedence for traffic matching a firewall policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy-based NAT because it is evaluated first

Policy-based NAT is evaluated before Central SNAT because it is directly tied to the firewall policy that matches the traffic. When a policy-based NAT rule exists for the same traffic, it takes precedence over Central SNAT rules, regardless of any global settings or rule IDs. Therefore, the source IPs from 192.168.1.0/24 will be translated to 203.0.113.10.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both translations will be applied, causing an error

    Why it's wrong here

    Policy-based NAT and Central SNAT do not stack. FortiGate selects a single source translation at session establishment; once a policy-based NAT rule matches the traffic, that translation is committed to the session table and the Central NAT lookup is never performed. The device does not generate an error from having both configured — the dispute is resolved by evaluation order rather than by applying both translations.

  • ✗

    Central SNAT because it is a global setting

    Why it's wrong here

    A 'global' Central NAT rule only fills the gap left when no policy-based NAT rule applies. Policy-based NAT is more specific because it is tied to an exact source/destination/service match in a firewall policy, so it takes precedence over the blanket Central SNAT rule. Central SNAT will be used only if the traffic is not matched by any policy-based NAT rule.

  • ✗

    The FortiGate will use the translation from the policy with the highest ID

    Why it's wrong here

    Policy ID is irrelevant when comparing policy-based NAT to Central NAT because the two NAT mechanisms are evaluated in separate phases. FortiGate first checks policy-based NAT rules for a match, and only if none match does it consult the Central SNAT table. Among multiple matching policy-based NAT rules, policy ID order might decide, but it cannot change the precedence between policy-based NAT and central NAT.

  • ✓

    Policy-based NAT because it is evaluated first

    Why this is correct

    FortiGate's NAT decision pipeline always evaluates policy-based NAT before Central NAT. When a session matches a firewall policy with an explicit NAT translation, that translation is applied immediately; Central SNAT rules are consulted only after no policy-based NAT rule matched. This design makes the more specific, policy-scoped translation authoritative, which is why traffic flows through the policy-based NAT rule.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.