NSE4 System and Network Administration Practice Question
An admin wants to ensure that traffic between two internal subnets (10.0.1.0/24 and 10.0.2.0/24) is inspected by the FortiGate but does not have its source IP translated. Which THREE configuration elements are required? (Choose three.)
⚠ Common exam trap
Watch out — candidates often assume static routes are always needed for inter-subnet routing, but FortiGate automatically creates connected routes for directly attached subnets, making static routes unnecessary in this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NAT disabled on that policy
When traffic between two internal subnets does not require source IP translation, NAT must be explicitly disabled on the firewall policy. By default, FortiGate policies may have NAT enabled (especially on outbound interfaces), so disabling NAT ensures the original source IP (10.0.1.x) is preserved when communicating with 10.0.2.x. This is configured by setting the 'set nat enable' option to 'disable' in the policy or unchecking NAT in the GUI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NAT disabled on that policy
Why this is correct
To preserve the original source IP of internal hosts when routing between subnets, the firewall policy must have NAT explicitly disabled. With NAT enabled, FortiGate would translate the source address to its own egress interface IP, which breaks end-to-end visibility, compromises logging, and can break return routing when the destination subnet has specifically crafted routes back to the real host address.
- ✗
A static route for each subnet on the FortiGate
Why it's wrong here
Because both subnets are directly connected to FortiGate interfaces, the kernel already installs connected routes in the routing table. Adding static routes for those directly connected subnets is redundant and can lead to routing loops or blackholes if the static route's next hop is incorrect or if the interface is down; the correct operation relies on connected routes alone, not on static entries.
- ✗
An IP pool for source NAT
Why it's wrong here
An IP pool is a source NAT address pool used to translate private source addresses to a range of public or alternative addresses. Applying an IP pool to the policy would again perform source address translation, which directly contradicts the goal of preserving original source IPs between internal subnets. IP pools are only appropriate when translating traffic leaving the FortiGate to an external network, not for pure routing between directly connected internal segments.
- ✓
A firewall policy allowing traffic between the two subnets
Why this is correct
A firewall policy is essential because FortiGate applies a default implicit deny action to all traffic not explicitly permitted between zones or interfaces. Even with correct routing and interface IPs, traffic between two subnets will be dropped unless a firewall policy exists with action ACCEPT matching the source and destination addresses. This policy enables forwarding and also allows you to attach security inspection features.
- ✓
Security profiles (e.g., antivirus, IPS) applied to the policy
Why this is correct
Security profiles such as antivirus, IPS, and web filtering are applied to firewall policies to enable layer 7 inspection, but they do not affect the routing or forwarding decision itself. They are optional for connectivity but required to inspect content for threats; common practice is to apply them to traffic between internal zones to prevent internal malware spread. These profiles work in flow-based or proxy-based modes and require the policy's action to be ACCEPT to take effect.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.