NSE4 Firewall Policies and NAT Practice Question
A FortiGate with multiple WAN interfaces uses policy-based routing (PBR) to route traffic from a specific subnet out of a particular interface. The admin also has a firewall policy allowing that subnet to the internet. However, the traffic is not being routed as expected. What could be the issue?
⚠ Common exam trap
Test-takers frequently assume firewall policy order or missing service definitions are the root cause, when in fact PBR's address matching is the precise mechanism that must be correctly configured for traffic to be routed as intended.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The PBR rule uses an incorrect source or destination address
Policy-based routing (PBR) is evaluated before firewall policies. If the PBR rule specifies an incorrect source or destination address, traffic from the intended subnet will not match the PBR rule and will fall through to the default routing table, potentially exiting via a different interface. The firewall policy alone cannot override the routing decision; the PBR rule must correctly identify the traffic to steer it to the desired egress interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall policy is placed above the PBR rule
Why it's wrong here
Firewall policies and policy routes are processed in separate stages: routing decisions happen first. A firewall policy placed above or below a PBR rule in the GUI has no effect on whether the PBR rule matches. Even if a firewall policy permits the traffic, the PBR rule is still evaluated earlier, so its lack of a match is unrelated to firewall policy placement.
- ✗
The PBR rule does not have a matching protocol or service defined
Why it's wrong here
A FortiGate policy route does not require a protocol or service to be defined; an omitted protocol field means 'any' (protocol 0), which broadens, not narrows, the match. Therefore, the absence of a protocol/service definition cannot prevent a PBR rule from matching traffic. The only effect is that the rule may match more traffic than intended, not less.
- ✓
The PBR rule uses an incorrect source or destination address
Why this is correct
Policy routes are matched against the source and destination addresses specified in the rule; if either address does not overlap the actual traffic's addresses, the PBR lookup will not produce a match. As a result, the traffic falls through to the regular routing table and may be sent out a different WAN interface. This is the most direct and common reason a PBR rule is silently ignored.
- ✗
The FortiGate is in transparent mode
Why it's wrong here
Transparent-mode FortiGate units operate at Layer 2 and do not route IP packets, so policy-based routing is not a supported feature in that mode. If the device were actually in transparent mode, the administrator could not have configured a functional PBR rule at all. Since the scenario states that policy-based routing is in use, the unit must be in NAT/route mode, making transparent mode an impossible explanation.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.