Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An admin needs to allow traffic from a specific IP to a web server on port 8080. The web server is behind a VIP that forwards port 80 to port 8080. When configuring the security policy, which destination should be used?

⚠ Common exam trap

The trap is that candidates may incorrectly select the real server IP (the post-NAT destination) instead of the VIP object. However, FortiGate checks the original destination IP against the policy, so the VIP object must be used as the destination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VIP object

When a VIP is used to translate the destination IP and port (e.g., from public IP:80 to private server IP:8080), the security policy must reference the VIP object as the destination. FortiGate matches the policy using the original destination IP before destination NAT is applied. The VIP object represents the original destination (the external IP) that clients use, so referencing it ensures the policy correctly permits the traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The virtual IP address of the FortiGate

    Why it's wrong here

    The external IP address of the FortiGate is merely an address; it is the VIP object that carries the NAT mapping to the internal server. When you set the destination in the firewall policy to the raw IP address instead of the VIP object, FortiGate treats it as a plain destination without translation logic. Consequently, inbound packets arriving at that IP will not be translated to the real server, or the policy may not match as intended because the VIP mapping is not associated with the policy.

  • ✗

    The real server IP address

    Why it's wrong here

    Setting the destination to the real server IP address directly means the FortiGate will forward traffic to that internal host without applying destination NAT. Since external clients send packets to the public VIP IP, a policy using the internal server IP would either never match those packets or would bypass the translation entirely. The VIP object must be used as the destination so that the public IP is correctly translated to the internal server IP.

  • ✓

    The VIP object

    Why this is correct

    The correct method is to define a firewall policy that uses the VIP object as the destination. The VIP object links the public IP to the internal server, and when a packet matches the policy, FortiGate automatically performs destination NAT, rewriting the destination to the real server IP. This policy also allows you to specify the allowed source IP, fulfilling the requirement to permit traffic from that specific IP to the web server.

  • ✗

    Any destination, because the VIP translates automatically

    Why it's wrong here

    Choosing 'any' as the destination will make the policy match all destinations, but it does not trigger VIP translation. The VIP object must be explicitly selected as the destination in the policy for destination NAT to occur. Without that explicit reference, even if the policy matches the traffic, FortiGate will not translate the destination address, and the web server will never receive the intended packets.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.