Which Policy Matches When Source Subnets Overlap?
A FortiGate has multiple firewall policies. Policy ID 1 allows HTTP from LAN to WAN. Policy ID 2 allows all traffic from DMZ to WAN. A packet arrives from the DMZ interface destined to a web server on the internet using HTTPS. Which policy is matched?
⚠ Common exam trap
Test-takers frequently assume a policy must explicitly list a service (like HTTPS) to match HTTPS traffic, but FortiGate policies with no service defined match all traffic, and the order of policies only matters when multiple policies match the same source and destination interfaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy ID 2, because it matches the source interface and destination
Policy ID 2 is matched because it allows all traffic from the DMZ interface to the WAN destination interface without any service restriction. The packet originates from the DMZ interface and is destined to the internet (WAN), so the source and destination interfaces match Policy ID 2. Since Policy ID 2 does not specify a service, it implicitly permits all protocols, including HTTPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy ID 1, because it is first in order
Why it's wrong here
FortiOS firewall policies are evaluated sequentially from top to bottom, but being first in the list is not sufficient to match a session. Policy ID 1 is indeed earlier, yet its source interface is 'LAN' while the HTTPS traffic enters on 'DMZ', so the interface pair does not match. Consequently, the evaluation skips policy 1 and continues down the policy table, meaning order alone does not determine eligibility.
- ✗
Policy ID 2, but only if it has a service allowing HTTPS
Why it's wrong here
Policy ID 2 is configured with the 'ALL' service, which in FortiOS is a predefined object that matches any IP protocol, TCP port, or UDP port, including HTTPS (TCP/443). Therefore, the phrase 'only if it has a service allowing HTTPS' is misleading because the policy already permits all services without further modification. The full set of criteria—source interface DMZ, destination interface WAN, and service ALL—is already satisfied, so no additional service object is needed.
- ✗
Implicit deny, because no policy matches HTTPS traffic
Why it's wrong here
FortiGate does have an implicit deny rule, but it acts only as the final entry after all explicit policies have been evaluated. In this scenario, Policy ID 2 explicitly allows the HTTPS session from DMZ to WAN, so the traffic is accepted before the evaluation process ever reaches the implicit deny. The implicit deny is an invisible, last-resort rule that drops and logs unmatched packets, yet it is never triggered when an earlier explicit allow policy matches the session.
- ✓
Policy ID 2, because it matches the source interface and destination
Why this is correct
Policy ID 2 is the correct match because it is the first policy whose source interface (DMZ) and destination interface (WAN) exactly correspond to the HTTPS traffic's ingress and egress. Its service is set to 'ALL', which encompasses HTTPS port 443, and its action is 'ACCEPT', meaning the firewall is explicitly configured to forward this session. Unlike Policy ID 1, which has mismatched interfaces, Policy ID 2 satisfies every required attribute for this traffic. Thus, it is the effective policy that permits the HTTPS traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.