NSE4 Firewall Policies and NAT Practice Question
A network admin has configured a firewall policy allowing traffic from the 'internal' zone to the 'external' zone. The policy uses a service object 'HTTP' (TCP/80). Users report they can access HTTP websites but not HTTPS. The admin confirms no other policies block HTTPS. What is the most likely cause?
⚠ Common exam trap
Many candidates assume a policy allowing HTTP will also allow HTTPS because both are web traffic, but FortiGate treats them as distinct services based on TCP port numbers, and implicit deny will block any unmatched traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTPS traffic is being dropped by implicit deny because no policy matches it
The firewall policy explicitly allows only HTTP (TCP/80) traffic from the internal zone to the external zone. HTTPS uses TCP/443, which is not included in the service object 'HTTP'. Since no other policy permits HTTPS, the traffic hits the implicit deny rule at the end of the policy list, which drops all unmatched traffic. This is the default behavior on FortiGate firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiGate needs to perform SSL inspection on HTTPS traffic
Why it's wrong here
SSL inspection (deep inspection) is an optional feature that decrypts HTTPS traffic for visibility and application control; it does not determine whether traffic is permitted by a firewall policy. A FortiGate can forward HTTPS traffic without any inspection as long as there is an explicit allow policy for service HTTPS (TCP/443). Even if SSL inspection is fully configured, a policy that only allows HTTP will not match HTTPS traffic, which is then dropped by implicit deny. Therefore, the lack of SSL inspection is not the cause of the problem.
- ✗
There is a policy ordering issue; a later policy might block HTTPS
Why it's wrong here
The policy ordering explanation is incorrect because the scenario explicitly states that there are no other firewall policies blocking HTTPS traffic. FortiGate processes policies in sequential order and uses the first match; however, if no policy matches HTTPS, the implicit deny rule at the end of the policy list always applies regardless of order. A later policy that denies HTTPS would only be relevant if an earlier policy allowed it, but here the only policy does not allow HTTPS in the first place. Thus, ordering is not a contributing factor.
- ✓
HTTPS traffic is being dropped by implicit deny because no policy matches it
Why this is correct
This is the correct explanation. In FortiOS, every firewall policy list ends with an implicit deny rule that silently drops any traffic that does not match an explicit allow policy. The administrator's policy only allows the HTTP service (TCP/80), so HTTPS traffic (TCP/443) has no matching allow entry and is consequently dropped by the implicit deny rule. This is a classic failure point when administrators assume that allowing HTTP also covers HTTPS, or forget to add a separate policy for HTTPS.
- ✗
The service object 'HTTP' also includes TCP/443 by default
Why it's wrong here
The built-in HTTP service object in FortiOS is defined to include only TCP port 80; it does not include TCP/443. HTTPS is a distinct service object in the FortiOS service catalog, and it must be explicitly selected in a policy to permit secure web traffic. If the service object HTTP included TCP/443, then HTTPS would have been allowed, but that is not how the predefined services behave. Therefore, this claim is false.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.