NSE4 System and Network Administration Practice Question
A FortiGate is configured with two WAN links (port1 and port2) and uses ECMP routing. The administrator wants to ensure that traffic from a specific internal subnet (192.168.10.0/24) always uses port1, while all other traffic uses ECMP. Which configuration should be applied?
⚠ Common exam trap
It's easy for candidates to confuse firewall policies with routing decisions; candidates often think a firewall policy can change the outgoing interface, but it only controls access, not the path traffic takes through the network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create two static routes with equal distances to use ECMP, and add a policy route for 192.168.10.0/24 with outgoing interface port1
Policy routes override the routing table for matching traffic, allowing you to force traffic from 192.168.10.0/24 out port1 while ECMP handles all other traffic. ECMP distributes traffic across multiple equal-cost routes, but a policy route takes precedence over the routing table for specified traffic. This meets the requirement without disrupting ECMP for other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a separate VDOM for 192.168.10.0/24 and route it through port1
Why it's wrong here
VDOMs are virtualization constructs that partition the FortiGate into independent virtual firewalls with separate routing tables and administrators. Creating a separate VDOM for 192.168.10.0/24 would require inter-VDOM links and policy routing between VDOMs, adding significant complexity and administrative overhead. For simple source-based egress control, policy routes within a single VDOM are the appropriate and much simpler method.
- ✓
Create two static routes with equal distances to use ECMP, and add a policy route for 192.168.10.0/24 with outgoing interface port1
Why this is correct
Equal-distance static routes create an ECMP group that load-balances traffic across port1 and port2, but this balances based on destination and may not honor source-based preferences. Adding a policy route for 192.168.10.0/24 with outgoing interface port1 forces all traffic originating from that source subnet to egress via port1, overriding the ECMP decision for that specific source. This combination gives you both the high-availability/load-balancing benefit of ECMP and the required source-specific egress control.
- ✗
Configure a VIP to translate 192.168.10.0/24 to an IP on port1
Why it's wrong here
A VIP is a destination NAT object used to map an external IP address and port to an internal server, typically for inbound port forwarding or server load balancing. It operates on the packet's destination before routing, but it does not determine the egress interface or next-hop for the traffic. Configuring a VIP on port1 would only translate the destination to an internal IP; it would not force 192.168.10.0/24 traffic to leave through port1. Routing decisions are made independently of NAT via the routing table.
- ✗
Use a firewall policy to change the route based on source
Why it's wrong here
Firewall policies in FortiGate are security controls that permit or deny traffic and apply profiles like IPS, antivirus, or NAT, but they do not participate in the route lookup process. In the packet processing flow, the FortiGate first matches the packet against policy routes and the routing table to determine the egress interface, and only then evaluates firewall policies for security enforcement. Therefore, a firewall policy cannot change the route or forcibly send traffic out a specific interface; that is the role of policy routes or route attributes.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.