NSE4 Firewall Policies and NAT Practice Question
An admin needs to allow traffic from a specific IP to a web server on port 8080. The web server is behind a VIP that forwards port 80 to port 8080. When configuring the security policy, which destination should be used?
⚠ Common exam trap
The trap is that candidates may incorrectly select the real server IP (the post-NAT destination) instead of the VIP object. However, FortiGate checks the original destination IP against the policy, so the VIP object must be used as the destination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VIP object
When a VIP is used to translate the destination IP and port (e.g., from public IP:80 to private server IP:8080), the security policy must reference the VIP object as the destination. FortiGate matches the policy using the original destination IP before destination NAT is applied. The VIP object represents the original destination (the external IP) that clients use, so referencing it ensures the policy correctly permits the traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The virtual IP address of the FortiGate
Why it's wrong here
The external IP address of the FortiGate is merely an address; it is the VIP object that carries the NAT mapping to the internal server. When you set the destination in the firewall policy to the raw IP address instead of the VIP object, FortiGate treats it as a plain destination without translation logic. Consequently, inbound packets arriving at that IP will not be translated to the real server, or the policy may not match as intended because the VIP mapping is not associated with the policy.
- ✗
The real server IP address
Why it's wrong here
Setting the destination to the real server IP address directly means the FortiGate will forward traffic to that internal host without applying destination NAT. Since external clients send packets to the public VIP IP, a policy using the internal server IP would either never match those packets or would bypass the translation entirely. The VIP object must be used as the destination so that the public IP is correctly translated to the internal server IP.
- ✓
The VIP object
Why this is correct
The correct method is to define a firewall policy that uses the VIP object as the destination. The VIP object links the public IP to the internal server, and when a packet matches the policy, FortiGate automatically performs destination NAT, rewriting the destination to the real server IP. This policy also allows you to specify the allowed source IP, fulfilling the requirement to permit traffic from that specific IP to the web server.
- ✗
Any destination, because the VIP translates automatically
Why it's wrong here
Choosing 'any' as the destination will make the policy match all destinations, but it does not trigger VIP translation. The VIP object must be explicitly selected as the destination in the policy for destination NAT to occur. Without that explicit reference, even if the policy matches the traffic, FortiGate will not translate the destination address, and the web server will never receive the intended packets.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.