NSE4 Firewall Policies and NAT Practice Question
A network admin configures a firewall policy allowing HTTP traffic from internal users to an external web server. The policy uses a service object 'HTTP' defined as TCP/80. However, users cannot reach the server. What is the MOST likely cause?
⚠ Common exam trap
Test-takers frequently assume HTTP traffic is always on port 80, but the question deliberately sets up a scenario where the server uses HTTPS (port 443), testing the understanding that firewall policies are port-specific and service objects must match the actual application protocol.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The external web server is using HTTPS (TCP/443) instead of HTTP
The firewall policy explicitly allows TCP/80 (HTTP), but the external web server is using TCP/443 (HTTPS). Since the service object does not match the actual traffic, the firewall will drop or reject the packets, preventing connectivity. This is a classic service mismatch issue in FortiGate firewall policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The external web server is using HTTPS (TCP/443) instead of HTTP
Why this is correct
The service object in this policy explicitly allows only TCP port 80 (HTTP). An external web server listening on TCP/443 (HTTPS) will not match this policy; FortiGate implicitly denies all traffic that does not match any explicit policy, so the client's HTTPS request is silently dropped. To permit the traffic, the admin must either change the service object to HTTPS (TCP/443) or create a separate policy with the correct service.
- ✗
The source address object does not include the users' subnet
Why it's wrong here
If the source address object is missing the users' subnet, the policy will not match any traffic originating from that subnet, causing those users to be blocked. However, this is a broader reachability issue and would likely affect all services from that subnet, not just HTTP vs HTTPS. The scenario specifically indicates an HTTP policy, so the more targeted cause is a service mismatch, not a source exclusion.
- ✗
The policy order is wrong; the policy is placed after a deny-all policy
Why it's wrong here
FortiGate evaluates policies in order and stops at the first match; a deny-all policy placed above this HTTP policy would preempt it and deny all HTTP traffic. While this is a valid misconfiguration, the symptom would be complete denial for the entire HTTP service, and the policy would show no hits. In contrast, a service mismatch (TCP/80 vs TCP/443) produces a more subtle problem where the policy appears correct but the server never responds to the expected port.
- ✗
The interface is set to the wrong zone
Why it's wrong here
Assigning the incoming interface to the wrong zone means this policy, which references a specific zone, will never be evaluated for traffic arriving on that interface. This misconfiguration would cause the policy to be silently bypassed, similar to a source error. However, interface zone misassignments are typically identified during initial setup, and the question's focus on HTTP service makes the service object mismatch a more likely and precise root cause.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.