NSE4 Firewall Policies and NAT Practice Question
An admin configures an IP Pool with type 'Overload' for outbound traffic from the 192.168.1.0/24 subnet. The pool uses a single public IP 203.0.113.10. After a few hours, users are unable to access external websites. The admin checks the session table and sees many sessions with the same public IP and different source ports. What is the most likely issue?
⚠ Common exam trap
Many candidates confuse 'Overload' with 'Static NAT' or think the issue is policy-related, but the key clue is the session table showing many sessions with the same public IP and different source ports, which directly points to source port exhaustion under PAT.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP Pool has run out of available source ports
The IP Pool is configured with type 'Overload' (Port Address Translation), which maps multiple internal hosts to a single public IP by using unique source ports. With a single public IP (203.0.113.10), the maximum number of concurrent sessions is limited by the available source ports (approximately 65,535 per IP, minus reserved ports). Once all source ports are consumed, new outbound sessions cannot be established, causing users to lose access to external websites.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session helper is misconfigured
Why it's wrong here
Session helpers (or application layer gateways) are used to dynamically open pinholes and rewrite payload for protocols like FTP, SIP, or H.323. They are not involved in the NAT port allocation process. A misconfigured session helper might cause specific protocol sessions to fail or interfere with signaling, but it cannot consume the source port pool or prevent new sessions from being created due to port exhaustion.
- ✓
The IP Pool has run out of available source ports
Why this is correct
With overload NAT (also called PAT or IP masquerading), all internal hosts are mapped to a single public IP address. The FortiGate must assign a unique source port number to each concurrent session per protocol (TCP and UDP have separate port spaces). The theoretical maximum is around 65,535 ports per protocol, minus reserved ports and those held in TIME_WAIT. When every available source port is already used, the IP pool becomes exhausted and the FortiGate cannot translate new sessions, causing connection failures for new traffic even though existing sessions continue to work.
- ✗
The IP Pool's public IP has been blacklisted by external websites
Why it's wrong here
If a public IP is blacklisted by external websites, those websites will reject connections from that IP, but that does not affect the FortiGate's ability to allocate source ports. Blacklisting would cause typical error messages or timeout failures for all traffic to those external sites, not just new sessions, and it would not exhaust the port pool. The root cause here is a local resource limitation (ports), not an external policy decision.
- ✗
The firewall policy is not referencing the IP Pool
Why it's wrong here
If the firewall policy did not reference the IP pool, the FortiGate would simply not apply dynamic PAT from that pool. The traffic might use the outgoing interface's IP address (if NAT is enabled via the interface) or would be translated differently, but it would not attempt to allocate ports from the pool. Consequently, the pool would never run out of ports; instead, you would see a different symptom like missing source NAT or wrong source address, not session failures caused by port exhaustion.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.