Courseiva
Firewall Policies and NAThardMultiple ChoiceObjective-mapped

NSE4 Firewall Policies and NAT Practice Question

A FortiGate has policy-based NAT enabled. The admin wants to translate the source IP of internal users to the interface IP for internet traffic. The firewall policy has NAT enabled. However, traffic from the internal network to the internet shows the original source IP instead of the interface IP. What is the MOST likely reason?

⚠ Common exam trap

A common mix-up: candidates assume per-policy NAT always works when enabled, but FortiGate's Central NAT feature can silently override it, making it appear as if NAT is broken.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Central NAT is enabled and overrides the per-policy NAT setting

When policy-based NAT is enabled, the per-policy NAT setting should translate the source IP to the interface IP. However, if Central NAT is also enabled, it takes precedence and overrides the per-policy NAT configuration. Central NAT uses its own rules (e.g., IP pools) and can prevent the interface IP translation from being applied, leaving the original source IP unchanged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Central NAT is enabled and overrides the per-policy NAT setting

    Why this is correct

    Central NAT is enabled and overrides the per-policy NAT setting. When central NAT is enabled in FortiOS, the per-policy NAT flag is ignored, and NAT is controlled exclusively by central NAT rules (source IP pools and destination VIPs). This means even if the policy shows NAT as enabled, the actual address translation is determined by the central NAT table, not the policy. Therefore, the admin would need to check the central NAT configuration to verify why NAT is not taking effect.

  • The destination is a VIP that disables NAT

    Why it's wrong here

    A VIP does not automatically disable source NAT on a policy. Virtual IPs are used for destination NAT, and while they map an external address to an internal server, source NAT (via IP pools) is a separate function. Unless the VIP is configured with an option to disable NAT for that specific policy (which is an intentional setting), the presence of a destination VIP alone does not override the policy's NAT flag. Thus, a VIP would not explain why NAT is being ignored unless explicitly configured to disable it.

  • The NGFW mode is set to profile-based

    Why it's wrong here

    The NGFW mode set to profile-based does not affect NAT functionality. Profile-based mode determines whether the firewall applies UTM profiles in flow or proxy manner, but it has no influence on address translation. NAT operations occur at the session level, independently of the inspection mode selected. Consequently, switching NGFW to profile-based would not cause the per-policy NAT setting to be overridden or ignored.

  • The policy is configured in proxy inspection mode

    Why it's wrong here

    Proxy inspection mode does not impact NAT operation. While proxy mode changes how traffic is processed by security engines, NAT translation is still performed at the network layer before the inspection engine sees the traffic. The policy's NAT flag remains authoritative when central NAT is disabled, regardless of whether the policy runs in flow-based or proxy-based inspection. Therefore, proxy mode is not the reason for NAT not being applied.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.