Courseiva

NSE4 Firewall Policies and NAT Practice Question

An admin configures an IP Pool with type 'Overload' for outbound traffic from the 192.168.1.0/24 subnet. The pool uses a single public IP 203.0.113.10. After a few hours, users are unable to access external websites. The admin checks the session table and sees many sessions with the same public IP and different source ports. What is the most likely issue?

⚠ Common exam trap

Many candidates confuse 'Overload' with 'Static NAT' or think the issue is policy-related, but the key clue is the session table showing many sessions with the same public IP and different source ports, which directly points to source port exhaustion under PAT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IP Pool has run out of available source ports

The IP Pool is configured with type 'Overload' (Port Address Translation), which maps multiple internal hosts to a single public IP by using unique source ports. With a single public IP (203.0.113.10), the maximum number of concurrent sessions is limited by the available source ports (approximately 65,535 per IP, minus reserved ports). Once all source ports are consumed, new outbound sessions cannot be established, causing users to lose access to external websites.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session helper is misconfigured

    Why it's wrong here

    Session helpers (or application layer gateways) are used to dynamically open pinholes and rewrite payload for protocols like FTP, SIP, or H.323. They are not involved in the NAT port allocation process. A misconfigured session helper might cause specific protocol sessions to fail or interfere with signaling, but it cannot consume the source port pool or prevent new sessions from being created due to port exhaustion.

  • ✓

    The IP Pool has run out of available source ports

    Why this is correct

    With overload NAT (also called PAT or IP masquerading), all internal hosts are mapped to a single public IP address. The FortiGate must assign a unique source port number to each concurrent session per protocol (TCP and UDP have separate port spaces). The theoretical maximum is around 65,535 ports per protocol, minus reserved ports and those held in TIME_WAIT. When every available source port is already used, the IP pool becomes exhausted and the FortiGate cannot translate new sessions, causing connection failures for new traffic even though existing sessions continue to work.

  • ✗

    The IP Pool's public IP has been blacklisted by external websites

    Why it's wrong here

    If a public IP is blacklisted by external websites, those websites will reject connections from that IP, but that does not affect the FortiGate's ability to allocate source ports. Blacklisting would cause typical error messages or timeout failures for all traffic to those external sites, not just new sessions, and it would not exhaust the port pool. The root cause here is a local resource limitation (ports), not an external policy decision.

  • ✗

    The firewall policy is not referencing the IP Pool

    Why it's wrong here

    If the firewall policy did not reference the IP pool, the FortiGate would simply not apply dynamic PAT from that pool. The traffic might use the outgoing interface's IP address (if NAT is enabled via the interface) or would be translated differently, but it would not attempt to allocate ports from the pool. Consequently, the pool would never run out of ports; instead, you would see a different symptom like missing source NAT or wrong source address, not session failures caused by port exhaustion.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.