Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate is set to NAT/Route mode. The admin wants traffic from internal users to the internet to use an IP address on the WAN interface for source NAT. Which configuration is required?

⚠ Common exam trap

Watch out — candidates often confuse virtual IP (VIP) for source NAT, but VIP is strictly for destination NAT (inbound traffic), whereas source NAT for outbound traffic requires enabling NAT on the firewall policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NAT on the policy from internal to WAN and set the outgoing interface to the WAN interface

In NAT/Route mode, source NAT (SNAT) is configured by enabling NAT on the firewall policy that governs traffic from the internal network to the WAN interface. When NAT is enabled on the policy and the outgoing interface is set to the WAN interface, FortiGate automatically translates the source IP of internal users to the primary IP address of that WAN interface (or a configured IP pool). This is the standard method for allowing internal users to access the internet with a public IP address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the FortiGate to transparent mode

    Why it's wrong here

    Transparent mode places the FortiGate as a Layer 2 bridge, forwarding frames based on MAC addresses without routing or network address translation. Since there is no routed WAN interface with a routable IP, the device cannot perform source NAT to a WAN address; transparent mode is designed for inline inspection, not for providing internet egress via NAT.

  • ✗

    Configure a policy route to force traffic through a specific interface

    Why it's wrong here

    Policy routes allow an administrator to override the routing table by specifying a next-hop or outgoing interface for matching traffic, but they are purely a routing function. NAT is an independent action applied within a firewall policy, and simply forcing traffic through a specific interface does not rewrite the source IP address, so the internal hosts would still send packets with their private IPs to the Internet.

  • ✗

    Configure a virtual IP mapping internal IPs to the WAN IP

    Why it's wrong here

    A virtual IP (VIP) is used for destination NAT, commonly to map an external WAN IP or port to an internal server for inbound traffic. Mapping internal IPs to the WAN IP would incorrectly apply to inbound destination address translation; it does not perform source NAT for outbound sessions initiated from the internal network, which is what the administrator needs for general Internet access.

  • ✓

    Enable NAT on the policy from internal to WAN and set the outgoing interface to the WAN interface

    Why this is correct

    This is the correct method for source NAT in NAT/Route mode. By enabling NAT on the firewall policy from internal to WAN and specifying the outgoing interface as the WAN interface, the FortiGate translates the source IP of each internal packet to the address of that WAN interface (or the configured IP pool), allowing return traffic to be routed back and enabling internal hosts to access the Internet using public addressing.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.