NSE4 Firewall Policies and NAT Practice Question
An admin configures a central SNAT rule to translate source IP 10.0.0.0/24 to IP pool 203.0.113.1-203.0.113.10 using overload (PAT). A policy-based NAT on a specific policy also translates the same source to the interface IP. Traffic from 10.0.0.0/24 to the internet shows source IP as the interface IP, not from the IP pool. What is the reason?
⚠ Common exam trap
Many exam-takers assume central SNAT rules are always evaluated first or that all NAT rules are additive, but FortiOS gives policy-based NAT higher priority, causing the central rule to be silently ignored when a conflicting policy-based translation exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy-based NAT overrides central SNAT rules
Policy-based NAT (PBNAT) takes precedence over central SNAT rules because it is applied directly to a specific firewall policy. When a policy matches traffic, its NAT configuration (including translation to the interface IP) is evaluated before any central SNAT rules. This override occurs regardless of the central SNAT rule's order or status, as PBNAT is considered more specific and thus higher priority in FortiOS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The central SNAT rule is disabled
Why it's wrong here
The central SNAT rule being disabled is not the root cause because precedence is determined by the NAT type configured on the policy, not by the enabled state of a central SNAT object. Even if the central SNAT rule were enabled, a policy with policy-based NAT (e.g., an IP pool assigned directly in the policy) will still take effect first. Disabling the central rule would only matter if no policy-based NAT existed, but here the policy explicitly defines its own NAT behavior.
- ✗
The policy is using fixed port range
Why it's wrong here
A fixed port range does not influence which NAT mechanism is chosen; it only restricts the range of source ports used when an IP pool is applied for allocation. The policy either selects policy-based NAT or relies on central SNAT regardless of how ports are managed. In this scenario, the fixed port range is simply a property of the policy's NAT settings and does not cause central SNAT to be ignored—the presence of an explicit per-policy NAT configuration is what overrides the central rule.
- ✓
Policy-based NAT overrides central SNAT rules
Why this is correct
This is correct because FortiOS applies policy-based NAT with higher priority than central NAT objects. When an administrator configures a source NAT directly on the firewall policy (such as selecting an IP pool), that per-policy NAT is evaluated before any central SNAT rule. The central NAT feature only serves as a fallback for policies that do not have their own NAT configuration, so the policy's own NAT action takes precedence and effectively masks the central SNAT rule.
- ✗
The IP pool is out of addresses
Why it's wrong here
Exhaustion of IP pool addresses would cause new sessions to fail address allocation, typically generating error logs or dropped packets, not silently reverting to the interface IP. Such a failure would occur after the policy has already selected the pool, meaning central SNAT never comes into play. Since the policy explicitly uses the pool, running out of addresses does not trigger a fallback to central SNAT or the interface IP; it simply breaks connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.