Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate with multiple VDOMs has a policy that allows traffic from VDOM A to VDOM B. The admin notices that traffic from VDOM A to a specific server in VDOM B is being dropped. The session log shows 'deny by forward policy check'. What is the MOST likely cause?

⚠ Common exam trap

Candidates often assume inter-VDOM traffic is implicitly allowed or that the source VDOM's policy controls the flow, but in reality each VDOM has its own independent policy set and the destination VDOM must have an explicit permit policy for the traffic to be forwarded.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy in VDOM B to allow traffic from VDOM A is missing or misconfigured

The session log message 'deny by forward policy check' indicates that the traffic was explicitly denied by a firewall policy rule, not by a routing or resource issue. In a multi-VDOM setup, traffic from VDOM A to VDOM B must be permitted by a policy in VDOM B (the destination VDOM) that allows traffic from the inter-VDOM link or from VDOM A. If that policy is missing or misconfigured, the FortiGate will drop the traffic and log this exact denial.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The inter-VDOM link is down

    Why it's wrong here

    If the inter-VDOM link were operationally down, the FortiGate would fail to establish the Layer 2 or Layer 3 adjacency between the two VDOMs, causing route lookup failures or 'no route to host' errors before any policy evaluation occurs. A down link prevents packets from ever reaching the destination VDOM's vdom, so the symptom would not be a forward policy denial. Since the scenario points to a policy-check failure in VDOM B, the link itself must be up and carrying the traffic.

  • ✗

    NAT is required for inter-VDOM traffic

    Why it's wrong here

    NAT is never a prerequisite for inter-VDOM traffic in FortiGate. Inter-VDOM links are treated as point-to-point virtual interfaces that route packets like any other interface, and the firewall can forward traffic between VDOMs using pure routing without address translation. NAT would only be necessary if overlapping IP address ranges were used or if the administrator explicitly wanted to hide internal addresses, but its absence does not cause a policy denial. Therefore, the lack of NAT does not explain a missing-policy error.

  • ✗

    The source VDOM has exceeded its session limit

    Why it's wrong here

    A per-VDOM session limit exhaustion would generate a specific error such as 'session table full' or 'session limit reached' and would affect all new sessions in that VDOM, not selectively deny traffic to a particular destination VDOM. Additionally, session limits are resource constraints that act during session establishment, whereas the error described is a forward policy check in the destination VDOM. The scenario's failure is a security-policy evaluation issue, not a resource exhaustion issue, so this option is incorrect.

  • ✓

    The policy in VDOM B to allow traffic from VDOM A is missing or misconfigured

    Why this is correct

    In a multi-VDOM FortiGate, traffic leaving VDOM A and entering VDOM B must match a forward policy in VDOM B that permits the traffic from the inter-VDOM link interface to the destination interface. If that policy is missing, misconfigured (e.g., wrong source/destination addresses, wrong service, or disabled action), the packet is implicitly denied by the firewall's default-deny behavior. The error message would reflect a forward policy check failure, making this the correct explanation for the traffic being blocked.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.