Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An administrator creates a firewall policy to allow outbound HTTP and HTTPS traffic from the internal network to the internet. The policy uses a dynamic IP pool for SNAT. Users report that some websites load slowly or fail to load intermittently. The administrator checks the firewall logs and sees 'session helper' warnings. What is the most likely cause?

⚠ Common exam trap

Candidates often confuse 'session helper' warnings with application-layer issues (like proxy latency or DNS) instead of recognizing it as a NAT resource exhaustion symptom tied to port range limitations in the IP pool configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IP pool is configured with fixed port range, limiting the number of available ports

The 'session helper' warnings indicate that the firewall is struggling to allocate NAT sessions for the dynamic IP pool. When the IP pool uses a fixed port range, the number of available source ports per IP is limited, leading to port exhaustion under heavy HTTP/HTTPS traffic. This causes intermittent failures and slow loads as new connections are dropped or queued.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy has traffic shaping enabled that is throttling the bandwidth

    Why it's wrong here

    Traffic shaping on a FortiGate policy limits the data rate per session or per source/destination, resulting in consistently lower throughput across all connections that match the policy. It would not selectively exhaust NAT resources or cause session helper (ALG) warnings, which are triggered only when address/port translation fails. Intermittent failures tied to the number of concurrent connections point to port exhaustion, not to bandwidth throttling.

  • ✗

    The firewall policy is configured for proxy-based inspection, causing high latency

    Why it's wrong here

    Proxy-based inspection processes traffic at the application layer, adding latency and requiring deep packet inspection, but it does not consume or constrain the pool of source ports used for NAT. While it could slow down session establishment, it would not produce session helper warnings, which indicate ALG/NAT translation issues rather than inspection delay. High latency is steady and uniform across sessions, which is unlike the intermittent, connection-count-dependent failures described in the scenario.

  • ✓

    The IP pool is configured with fixed port range, limiting the number of available ports

    Why this is correct

    A fixed port range in an IP pool restricts the translated source ports to a narrow set, such as 1024–2048, drastically capping the number of concurrent NAT sessions per pool address. Once those ports are exhausted, new outbound connections fail intermittently until old sessions time out, exactly matching the reported symptoms. Session helper warnings, such as for FTP or ICMP, appear because the helper cannot allocate a NAT port for the associated data channel, confirming that the IP pool port configuration is the root cause.

  • ✗

    The DNS server on the internal network is misconfigured

    Why it's wrong here

    A misconfigured internal DNS server would cause hostname resolution to fail or time out, making outbound connections either completely unreachable or delayed by DNS retries, but it would not already-established sessions or generate session helper warnings. DNS issues are independent of the firewall's NAT engine and would not be intermittent based on the number of concurrent sessions. The reported symptoms of port exhaustion and ALG warnings are tied to firewall NAT resources, not to DNS infrastructure.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.