NSE4 High Availability and Diagnostics Practice Question
An administrator is troubleshooting an issue where users cannot access an internal web server via the internet through a FortiGate. The FortiGate has a virtual IP (VIP) configured for the web server. The administrator runs 'diagnose debug flow filter daddr <public-ip>' and 'diagnose debug flow trace start 100'. The output shows 'msg: forward to x.x.x.x via intf port2' but then 'msg: policy deny'. Which TWO actions should the administrator take to resolve the issue? (Choose two.)
⚠ Common exam trap
NSE4 often tests the interpretation of 'diagnose debug flow' output, and candidates may focus on routing or DNS instead of recognizing that 'policy deny' points directly to a firewall policy mismatch in source interface or destination address.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm that the firewall policy's destination is set to the internal web server's IP address (or the VIP's mapped IP)
Option C is correct because when a VIP is used, the firewall policy must reference the VIP object (or its mapped internal IP) as the destination; if the policy destination is left as 'all' or points to the wrong address, the flow trace will show 'policy deny' even though the packet is forwarded toward port2. Option D is correct because the policy permitting inbound access must match the actual ingress interface (the WAN interface where the public IP is reached); if the source interface is set to the internal/LAN interface or 'any' incorrectly, the policy lookup fails and produces 'policy deny'. Option A is not the issue here since the trace already shows the packet being forwarded out via intf port2, meaning routing toward the server exists and the deny occurs at policy evaluation, not at the routing stage. Option B is irrelevant because DNS resolution only affects name-to-IP mapping and would not cause a FortiGate policy deny for an already-arriving packet. Option E is unnecessary because the VIP is functioning (traffic is being forwarded), and changing the port would not fix a policy-match failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure that a static route exists to the internet via the WAN interface
Why it's wrong here
The traffic in question is inbound, arriving on the WAN interface from the internet. The FortiGate does not use a route to the internet to accept this traffic; routing is consulted only for the return packet, and the default route via WAN is typically already present. The debug output shows that DNAT is already occurring, so the actual problem lies in the firewall policy lookup after the destination is translated. Adding or modifying a static route would not influence the policy matching that is currently causing the traffic to be dropped.
- ✗
Check if the public DNS resolution for the domain is correct
Why it's wrong here
DNS resolution occurs on the client side, before any packet is sent to the FortiGate. The user's browser resolves the domain name to the VIP's public IP address, and the subsequent TCP connection is initiated directly to that IP. Since the debug flow clearly shows packets reaching the FortiGate and being processed for NAT, the DNS record must be valid and pointing to the correct address. The failure is happening at the firewall policy layer after NAT, which is completely independent of DNS resolution.
- ✓
Confirm that the firewall policy's destination is set to the internal web server's IP address (or the VIP's mapped IP)
Why this is correct
After DNAT, the destination IP changes to the internal server. The firewall policy must allow traffic to that internal IP. If the policy's destination is set to the VIP's public IP, it may not match post-DNAT. The correct approach is to set the destination to the mapped IP address.
- ✓
Verify that the firewall policy allowing the traffic has the correct source interface (WAN)
Why this is correct
After destination NAT is applied, the packet's ingress interface remains the WAN interface, and the FortiGate's firewall policy lookup uses this original ingress zone to match the policy. If the policy's source interface is incorrectly set to the internal interface, the inbound traffic arriving from the internet will not match any policy rule and will be silently dropped. Therefore, to permit the translated traffic, the policy must specify the WAN interface (or the appropriate WAN zone) as the source interface.
- ✗
Recreate the virtual IP object with a different port
Why it's wrong here
The debug output already shows that the Virtual IP (VIP) is matching and the destination address is being translated to the internal server's IP. That demonstrates the VIP object is configured correctly for the existing public IP and port. Recreating the VIP with a different port would not change the fundamental issue: the subsequent firewall policy does not have an allow rule with the correct post-DNAT destination. Modifying a working VIP would introduce new configuration mismatches and would not resolve the policy lookup failure.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.