NSE4 Firewall Policies and NAT Practice Question
An administrator creates a firewall policy with a traffic shaper to limit bandwidth for guest wireless users. After applying the policy, users can still consume high bandwidth. The administrator confirms the policy is matching. What is the MOST likely reason the traffic shaper is not effective?
⚠ Common exam trap
Many candidates assume creating a traffic shaper automatically applies it to all matching traffic, but FortiGate requires explicit assignment in the firewall policy's shaper field to enforce the limit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic shaper is configured but not applied to the policy's 'Traffic Shaper' field
In FortiGate, a traffic shaper must be explicitly selected in the 'Traffic Shaper' field of the firewall policy to be applied. Simply creating a shaper and configuring it is insufficient; the policy's shaper field links the shaper to the traffic. Without this link, the shaper is not enforced, even if the policy matches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic shaper's maximum bandwidth is set too high
Why it's wrong here
A traffic shaper with a maximum bandwidth of, say, 100 Mbps still enforces a hard ceiling; traffic cannot exceed that value even if the network is idle. If the configured maximum is so high that actual traffic never approaches it, the shaper never 'trips' and the symptom looks exactly like no shaping at all. However, that is not the same as having unlimited bandwidth — the limit exists, just at an unrealistic threshold. In this scenario, the 'high bandwidth consumption' suggests there is no effective cap, which points to a missing assignment rather than a too-high ceiling.
- ✗
The traffic shaper is applied to the wrong direction (egress vs ingress)
Why it's wrong here
On FortiGate, a traffic shaper is attached to a firewall policy as either an egress (outbound) or ingress (inbound) shaper. If you attach the correct shaper name but to the wrong direction, it simply has no effect on the traffic flowing the other way — e.g., an egress shaper doesn't touch ingress packets. Because the policy's direction is usually defined by its source/destination interfaces, the admin would normally select the correct direction; a direction error would still exhibit unshaped bandwidth, but it would also be inconsistent with the rest of the policy. The most likely cause is that the shaper is not referenced at all, not that it is referenced in the wrong direction.
- ✓
The traffic shaper is configured but not applied to the policy's 'Traffic Shaper' field
Why this is correct
FortiGate traffic shapers are objects that must be explicitly referenced in a firewall policy; simply creating a shaper under Traffic Shaping does not cause any policy to use it. The firewall policy's 'Traffic Shaper' field and 'Per-IP Shaper' field both default to 'None', which means traffic matching the policy is forwarded with no bandwidth limitation. To enforce a shaping rule, the administrator must select the desired shaper in that drop-down field. When the shaper is left unassigned, the policy passes traffic at full interface speed, perfectly explaining the 'high bandwidth consumption' symptom.
- ✗
The traffic shaper is a per-IP shaper but the policy applies to a subnet
Why it's wrong here
A per-IP shaper is specifically intended to be used with policies whose source is a subnet or IP range; it applies a separate bandwidth quota to each individual source IP. For example, if the policy sources 192.168.1.0/24, the FortiGate automatically enforces the per-IP limit for every host in that subnet, so the shaper definitely takes effect. Therefore, using a per-IP shaper on a subnet does not disable traffic shaping. If the admin sees no shaping, it's more likely that the shaper was not selected in the policy's 'Per-IP Shaper' field, or that a different shaper type was accidentally used.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 282-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.