NSE4 Firewall Policies and NAT Practice Question
An admin configures a Central SNAT rule to translate internal 192.168.1.0/24 to 203.0.113.10 when accessing the internet. However, traffic from 192.168.1.100 to 8.8.8.8 shows source IP 192.168.1.100 in logs. What is the MOST likely cause?
⚠ Common exam trap
Candidates may confuse IP pool override with Central SNAT, but if an IP pool were active, the source would be changed to the pool IP. Here, the source remains the original internal IP, indicating the Central SNAT rule itself is not matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Central SNAT rule is applied to the wrong outgoing interface
The Central SNAT rule is not being applied to the traffic. The most likely cause is that the rule specifies an outgoing interface different from the one used to reach 8.8.8.8, so the rule does not match and no source translation occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Central SNAT rule is disabled
Why it's wrong here
If the Central SNAT rule were disabled, FortiOS would simply not consider it during session setup, leaving the original source IP unchanged in the packet header. That could produce a "no translation" log entry, but in practice an admin who just created the rule typically leaves it enabled. Moreover, a disabled rule cannot explain why the translation is absent when an IP pool is attached to the matching firewall policy, because that override occurs regardless of the central rule's state.
- ✓
The Central SNAT rule is applied to the wrong outgoing interface
Why this is correct
Central SNAT rules specify an outgoing interface, and if the interface does not match the actual egress interface used by the traffic, the rule is skipped and no translation occurs. However, in a typical policy-based NAT deployment, the firewall policy's IP pool takes precedence over any central SNAT rule, regardless of interface matching. This makes an interface mismatch a possible but less likely explanation, because the override would still mask the central rule even if the interface were correct.
- ✗
The firewall policy has an IP pool configured, overriding Central SNAT
Why it's wrong here
In FortiOS, when a firewall policy has an IP pool configured, that policy-based NAT is evaluated before any Central SNAT rule and takes precedence. The session's source address is translated according to the IP pool, and the Central SNAT rule is effectively bypassed, so no translation from that rule is visible in the logs. This is the most common cause of "no translation" when a Central SNAT rule exists but a policy with an IP pool also matches the traffic.
- ✗
The destination address in the Central SNAT rule is incorrect
Why it's wrong here
A Central SNAT rule's destination address must match the traffic's destination for the rule to apply; if the rule specifies a destination that does not include 8.8.8.8, the rule is not matched and no translation occurs. Yet in typical internet-bound traffic, the rule is often configured with a destination of "all" or a broad address range, making this an unlikely oversight. More importantly, even with a correct destination, an IP pool on the firewall policy would override the Central SNAT rule, so the real cause is the policy-level NAT.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.