NSE4 Firewall Policies and NAT Practice Question
An admin needs to allow inbound SMTP traffic from the internet to a mail server in the DMZ. The public IP is 203.0.113.10, and the mail server's private IP is 10.0.0.5. Which VIP configuration is correct?
⚠ Common exam trap
Test-takers frequently confuse port numbers or assume that any port mapping will work, but the NSE4 exam specifically tests that the VIP must match the service port (SMTP = 25) and that only the correct port mapping enables the intended application traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VIP: external IP 203.0.113.10 port 25 -> internal IP 10.0.0.5 port 25
It configures a Virtual IP (VIP) that maps the public IP 203.0.113.10 on TCP port 25 (SMTP) to the internal mail server IP 10.0.0.5 on port 25. This allows inbound SMTP traffic from the internet to reach the mail server in the DMZ, performing both destination NAT (DNAT) and port forwarding for the specific SMTP service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VIP: external IP 203.0.113.10 port 25 -> internal IP 10.0.0.5 port 25
Why this is correct
This is the correct configuration because SMTP traffic uses TCP port 25 by default. The virtual IP (VIP) maps the external address 203.0.113.10:25 to the internal mail server's SMTP listener on 10.0.0.5:25, performing destination NAT without altering the destination port. This allows inbound mail delivery to reach the actual service that speaks the SMTP protocol.
- ✗
VIP: external IP 203.0.113.10 port 25 -> internal IP 10.0.0.5 port 80
Why it's wrong here
This configuration is invalid because it translates the SMTP port 25 to port 80, which is the well-known port for HTTP. The internal mail server would receive the connection on its HTTP service, but the client is speaking SMTP, not HTTP. The mail server's SMTP daemon is not listening on port 80, so the TCP handshake may succeed but the SMTP exchange will fail.
- ✗
VIP: external IP 203.0.113.10 all ports -> internal IP 10.0.0.5 all ports
Why it's wrong here
Mapping the entire external IP address and all ports to the internal server is overly broad and insecure. It effectively creates a one-to-one NAT that exposes every service running on 10.0.0.5 to the internet, including potentially exploitable administrative or file-sharing ports. A VIP for SMTP should be scoped to only the necessary TCP port 25 to minimize the attack surface.
- ✗
VIP: external IP 203.0.113.10 port 80 -> internal IP 10.0.0.5 port 80
Why it's wrong here
This VIP maps port 80 to port 80, which is the HTTP port. Inbound SMTP traffic arrives on port 25, so this VIP would never match the traffic that needs to be forwarded. Even if the traffic were on port 80, it would be HTTP, not SMTP, and would not enable mail delivery to the internal server.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.