Courseiva

NSE4 Firewall Policies and NAT Practice Question

An admin needs to configure a FortiGate to allow multiple internal servers to be accessible from the internet using the same public IP but different ports. For example, internal server A (192.168.1.10:80) should be reachable via 203.0.113.10:8080, and internal server B (192.168.1.20:443) via 203.0.113.10:8443. Which TWO configuration steps are required?

⚠ Common exam trap

Candidates often think a single VIP with multiple port mappings can handle different internal servers, but FortiGate VIPs are one-to-one mappings; a VIP group is required to aggregate multiple VIPs under one policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create two separate VIPs, one for each server, and add them to a VIP group

Each internal server requires a unique Virtual IP (VIP) to map a specific external port to a specific internal IP and port. Adding these VIPs to a VIP group allows a single firewall policy to reference all of them, enabling the FortiGate to differentiate traffic based on the destination port and forward it to the correct internal server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create two separate VIPs, one for each server, and add them to a VIP group

    Why this is correct

    A VIP group aggregates multiple Virtual IP (VIP) objects into a single destination address object. Each VIP in the group has its own external-to-internal IP/port mapping, so when the group is used as a policy destination, the FortiGate checks the inbound packet against each VIP member, performs the matching DNAT, and forwards to the correct internal server. This design is the only way to expose two different internal servers through distinct public IPs/ports under one logical policy.

  • ✗

    Disable NAT on the policy to preserve the source IP

    Why it's wrong here

    The policy's NAT setting controls source NAT for traffic leaving the FortiGate, not destination translation for inbound sessions. When a VIP is matched, the FortiGate already rewrites the destination IP/port to the internal server; disabling NAT simply means no source IP translation is applied to the outgoing packet. This option does not create any mapping for the second server and is irrelevant to the requirement of reaching multiple internal destinations.

  • ✓

    Configure a firewall policy with destination set to the VIP group and action set to allow

    Why this is correct

    After creating the VIP group, this firewall policy is the actual access control rule that permits the traffic. With action 'Accept' and the VIP group as the destination, the FortiGate allows the inbound session, then translates the destination to the appropriate internal server via the VIP group member. Without such a policy, even correctly defined VIPs would not forward any traffic, because FortiOS always requires a matching accept policy for the session to pass.

  • ✗

    Configure Central SNAT to translate the source IP

    Why it's wrong here

    Central SNAT is a feature for source address translation of outbound sessions initiated by internal hosts; it operates on the source address when the session leaves toward an external network. For inbound traffic arriving at a VIP, the source is already the remote client, and the VIP performs destination NAT rather than source NAT. Configuring Central SNAT would not provide a mapping to the two internal servers, nor would it replace the need for VIPs and an allow policy.

  • ✗

    Create a single VIP with port forwarding that maps multiple ports

    Why it's wrong here

    A FortiOS VIP with port forwarding maps a single external IP/port (or port range) to one internal IP and its port. It cannot translate the same external destination to two different internal server IP addresses, because the VIP object has only one 'mapped-address' value. To publish two distinct servers, you must create two VIP objects — one per server — and then optionally place them in a VIP group; a single VIP cannot dynamically choose a server based on the requested port.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.