Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate has a policy that allows traffic from 10.0.0.0/8 to any destination with NAT enabled using an IP pool 'Pool1' (203.0.113.10-203.0.113.20). The admin notices that internal servers using fixed ports (e.g., SIP) are failing. What is the likely cause?

⚠ Common exam trap

It's easy for candidates to assume any IP pool will preserve source ports, but overload (PAT) mode explicitly changes them, which breaks applications that require fixed source ports like SIP, DNS, or TFTP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IP pool is configured with overload (PAT), which changes source ports

When an IP pool is configured with overload (PAT), the FortiGate translates the source IP address and also changes the source port to a random high port. For protocols like SIP that rely on fixed source ports (e.g., UDP 5060), this port remapping breaks the application because the SIP server expects traffic from a specific port. Option D correctly identifies this as the root cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy order is incorrect

    Why it's wrong here

    Policy order determines which firewall rule matches first based on source, destination, and service, but it does not control how NAT translates addresses or ports. Even if you reorder policies so this traffic is matched earlier, the NAT IP pool configuration still defines port behavior. Since the policy references an IP pool that changes source ports, reordering cannot prevent the port translation that breaks SIP. The failure originates in NAT, not in policy sequence.

  • ✗

    The IP pool is configured with one-to-one NAT

    Why it's wrong here

    A one-to-one NAT IP pool statically maps a single internal IP to a single external IP, leaving source ports untouched. With one-to-one NAT, the original SIP source port (e.g., 5060) would be preserved, so signaling and media would continue to work correctly. Because the symptom is a port change, this configuration cannot be the cause—in fact, it would avoid the problem entirely. Thus, this answer incorrectly identifies a NAT mode that does not modify ports.

  • ✗

    The IP pool uses fixed port range, which should work

    Why it's wrong here

    Fixed port range (also known as static PAT) maps a specific internal port to a specific external port from a predefined pool, preserving the original source port as long as it is within the range. For SIP, which relies on well-known ports for signaling, a fixed port range would keep the source port intact, allowing the protocol to function. The issue described arises only when ports are dynamically changed, not when they are fixed. Therefore, this configuration would not cause the failure.

  • ✓

    The IP pool is configured with overload (PAT), which changes source ports

    Why this is correct

    Overload (PAT) translates many internal IPs to a single external IP by dynamically assigning unique source ports for each session. This changes the original SIP source port (e.g., 5060) to some random high port, breaking protocol expectations because SIP and RTP require consistent port mapping. The FortiGate's overload mode is exactly the condition that alters ports, leading to call setup and media failures. Thus, this is the correct explanation for the reported symptom.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.