Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate is deployed in NAT/Route mode. The administrator wants to create a policy that allows internal users to access the internet and also translates their private IP addresses to the public IP of the FortiGate's WAN interface. Which policy configuration is required?

⚠ Common exam trap

Many candidates confuse source NAT (enabled on the firewall policy) with destination NAT (configured via VIPs) or mistakenly think NAT is a routing feature, leading them to select options like static route with NAT or VIP configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NAT on the firewall policy

In NAT/Route mode, enabling NAT on the firewall policy performs source NAT (SNAT) by default, translating the private source IP addresses of internal users to the public IP address of the FortiGate's WAN interface. This is the standard method for allowing internal users to access the internet while hiding their private addresses behind a single public IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a virtual IP (VIP) for the WAN interface

    Why it's wrong here

    A virtual IP (VIP) on the WAN interface is a destination NAT construct, translating an incoming packet's destination address (e.g., a public IP to a private server IP). It does not touch the source IP of outbound sessions. Therefore, while VIPs are essential for inbound port forwarding or load balancing, they cannot perform the source translation needed for outbound traffic from the internal network to the Internet.

  • ✗

    Set the policy action to ACCEPT and enable SNAT in the policy advanced options

    Why it's wrong here

    There is no dedicated SNAT toggle in FortiOS policy advanced options; source NAT is implicitly controlled by the 'NAT' checkbox on the main policy page. Even with the action set to ACCEPT, without enabling NAT, the FortiGate will simply route traffic without modifying the source address, causing return packets to fail if the source IP is private. Thus, attempting to 'enable SNAT in advanced options' is a nonexistent configuration step.

  • ✗

    Add a static route with NAT enabled

    Why it's wrong here

    Static routes in FortiOS are purely L3 next-hop statements and carry no NAT or translation attributes. The route merely tells the FortiGate where to forward packets; address translation is a separate function anchored to firewall policies. Even if you could tag a route with NAT, there is no interface or policy context to define the translated source IP, so this option is fundamentally invalid.

  • ✓

    Enable NAT on the firewall policy

    Why this is correct

    Enabling NAT on the firewall policy is the explicit mechanism for source NAT in NAT/route mode. When checked, the FortiGate overwrites the source IP of matching outbound sessions with the IP address of the egress interface (or an IP pool if configured). This is the correct and minimal configuration to allow internal private hosts to initiate Internet-bound sessions.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.