Courseiva
Firewall Policies and NAT →mediumMultiple Select

NSE4 Firewall Policies and NAT Practice Question

An admin needs to create a firewall policy that allows SMTP traffic (TCP/25) from the internal network (10.0.0.0/24) to a mail server in the DMZ (172.16.1.10). Additionally, the admin wants to ensure that the mail server can only be accessed by the internal network, not from the internet. Which THREE settings must be configured in the firewall policy? (Choose three.)

⚠ Common exam trap

It's easy for candidates to think NAT is required for traffic between internal and DMZ zones, but FortiGate does not require NAT for inter-zone traffic unless the destination network is private and overlapping, and the question explicitly wants to restrict access from the internet, not translate addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Source interface set to 'internal'

The source interface must be set to 'internal' to restrict the firewall policy to traffic originating from the internal network (10.0.0.0/24). This ensures that only hosts on the internal interface can reach the mail server, effectively blocking any internet traffic that would arrive on a different interface like 'wan'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Source interface set to 'internal'

    Why this is correct

    The source interface is a mandatory field in a FortiGate firewall policy that identifies the ingress interface through which traffic enters the firewall. For internal clients reaching an SMTP server in the DMZ, setting the source interface to 'internal' ensures the policy only matches traffic arriving from the trusted internal segment. Without this specific interface binding, the policy could unintentionally match traffic from other interfaces, creating a security exposure. This interface pair is the first classification criterion that FortiGate uses when building a session.

  • ✗

    Set schedule to 'always'

    Why it's wrong here

    The schedule is an optional policy attribute that defines the time window when the policy is valid. Setting it to 'always' simply means the policy is active 24/7 and has no effect on the traffic's source, destination, or service; it neither enables nor restricts SMTP. Since the core requirement is to allow SMTP traffic from internal to dmz, the schedule does not influence that decision. A schedule of 'always' is acceptable but irrelevant to the question's main objective, so it is not a required or defining element.

  • ✓

    Destination interface set to 'dmz'

    Why this is correct

    The destination interface is a mandatory policy field that specifies the egress interface where traffic exits the FortiGate. Because the SMTP server resides on the DMZ segment, the policy must set the destination interface to 'dmz' so that only traffic leaving toward that network is matched. This interface pairs with the source interface to define the zone-to-zone path and ensures the policy does not accidentally apply to traffic headed to the WAN or internal networks. It is an integral part of the traffic classification tuple in FortiGate.

  • ✓

    Service set to 'SMTP'

    Why this is correct

    The service field defines the exact protocol and port(s) allowed by the policy. The 'SMTP' service object in FortiGate matches TCP port 25, which is the standard port for Simple Mail Transfer Protocol. Setting the service to 'SMTP' is what explicitly permits SMTP traffic while all other services are implicitly denied by the default-deny rule at the end of the policy table. This is the critical element that makes the policy an SMTP allow rule rather than a blanket permit for all IP traffic.

  • ✗

    Enable NAT to translate source IP

    Why it's wrong here

    NAT (Network Address Translation) is an optional policy action that modifies the source IP address as traffic traverses the FortiGate. In a typical internal-to-DMZ scenario, both networks use private IP addresses that are routable between them, so no source IP translation is required. Enabling NAT would replace the internal client's source IP with the FortiGate's DMZ interface address, potentially breaking server-side logs or access controls that rely on the original client IP. Since the question only asks for allowing SMTP, NAT is unrelated to the allow decision and unnecessary for connectivity here.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.