NSE4 Firewall Policies and NAT Practice Question
An administrator needs to allow inbound SSH access from the internet to a specific internal server (10.0.1.10) on port 22. The WAN IP is 203.0.113.10. Which THREE configuration steps are required?
⚠ Common exam trap
Many exam-takers assume configuring a VIP alone is sufficient, forgetting that a firewall policy must also be created to permit the translated traffic, and they may confuse source NAT (Option C) with destination NAT required for inbound access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the firewall policy allows the SSH service (port 22)
Option D is correct because a Virtual IP (VIP) performs destination NAT (DNAT), mapping the public WAN address 203.0.113.10 on port 22 to the internal server 10.0.1.10 on port 22, which is the essential first step to make the internal host reachable from the internet. Option B is correct because a firewall policy must be created with the incoming interface as WAN and the outgoing interface as the internal/LAN interface, with the destination set to that VIP object, so the firewall permits and forwards the translated traffic to the server. Option A is correct because the policy must explicitly allow the SSH service on TCP port 22, since inbound traffic is denied by default and the service must be matched in the policy for the connection to be accepted. Option C is incorrect because a source NAT IP pool applies to outbound traffic (masquerading internal clients behind a public address) and is irrelevant to publishing an internal server for inbound SSH. Option E is incorrect because SSL inspection applies to TLS/HTTPS traffic and cannot inspect SSH, which is not an SSL/TLS protocol, so enabling it would not enable or secure this inbound SSH access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure the firewall policy allows the SSH service (port 22)
Why this is correct
Traffic arriving at the FortiGate for the public IP and port 22 must be matched by a firewall policy whose destination is the VIP's mapped address (the private server IP) and whose service includes SSH. Without a policy that explicitly allows port 22/TCP as the service, the FortiGate will drop the session even if the VIP object exists and is correctly configured. Remember that on FortiGate, an inbound DNAT translation (VIP) does not automatically permit traffic; the policy is the only place where the action (accept) is decided.
- ✓
Create a firewall policy from WAN to internal interface with destination set to the VIP
Why this is correct
For inbound SSH to a mapped server, the policy must be placed on the ingress (WAN) interface, with the source usually all or specific admin hosts, and the destination object set to the firewall's VIP. The destination of this policy must be the VIP object rather than the raw public IP, because FortiGate consults the policy after performing destination translation; setting the destination to the VIP ensures the session is permitted post-translation. Also, the policy must have NAT enabled (implicitly default) to apply the VIP's DNAT to the internal address, and the action must be ACCEPT to allow the connection.
- ✗
Configure a source NAT IP pool for outbound traffic
Why it's wrong here
Source NAT (SNAT) is used for outbound traffic leaving an interface to replace the source address, whereas inbound SSH requires destination NAT to translate the public destination to the private server. Configuring an IP pool for outbound traffic has no effect on how the FortiGate handles incoming connection requests to port 22; the session's destination remains the public IP until a VIP/DNAT is applied. Moreover, on FortiGate an IP pool is used with central SNAT or via the policy option Use IP Pool and would not solve the need to translate the inbound destination.
- ✓
Create a Virtual IP (VIP) mapping 203.0.113.10:22 to 10.0.1.10:22
Why this is correct
A virtual IP (VIP) object on FortiGate creates a one-to-one DNAT mapping between an external IP:port (203.0.113.10:22) and an internal IP:port (10.0.1.10:22), allowing the firewall to forward inbound SSH to the private server. This mapping is what makes the private server reachable from the internet without assigning a public address directly to the server's interface. In the VIP, you must set the mapped service to TCP/22 and enable port forwarding, so only SSH traffic to the public IP is translated; otherwise the VIP would match all ports. The VIP itself only performs translation; it does not authorize the session — the separate firewall policy must still allow it.
- ✗
Enable SSL inspection on the policy
Why it's wrong here
SSH encryption is not SSL/TLS; enabling SSL inspection on the policy would require a CA-issued certificate and would attempt to decrypt HTTPS traffic, but SSH uses its own transport protocol on port 22 and cannot be decrypted by FortiGate's SSL proxy. Even if the policy did inspect SSL, inspection does not affect whether the traffic is allowed — it only enables deeper visibility for HTTP/HTTPS. Adding SSL inspection would add overhead and potentially break the SSH session because the firewall would need to re-encrypt after inspection, and there is no decryption support for SSH. Thus it is irrelevant to allowing inbound SSH.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.