Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An administrator needs to allow VoIP traffic from a remote branch (192.168.2.0/24) to the main office (10.0.0.0/8) using UDP ports 5060 and 10000-20000. What is the most efficient way to define the service in the firewall policy?

⚠ Common exam trap

Many exam-takers assume a single port range (5060-20000) is acceptable for efficiency, overlooking the security risk of opening unnecessary ports, or they mistakenly rely on the predefined 'VoIP' service object without verifying its exact port definitions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a service group containing both service objects

Creating a service group allows you to combine two separate service objects (one for UDP 5060 and one for UDP 10000-20000) into a single logical group, which can then be applied in one firewall policy. This is the most efficient method as it avoids duplicating policies or using an overly broad port range, and it leverages FortiGate's service group feature for clean, manageable rule sets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a service group containing both service objects

    Why this is correct

    Creating a service group that contains both the SIP service object (UDP/TCP 5060) and the RTP service object (UDP 10000-20000) lets a single firewall policy match the full VoIP call flow. This is the correct approach because FortiGate service groups are logical sets of service objects that allow you to consolidate multiple protocols without expanding the policy count.

  • ✗

    Use a custom service object with port range 5060-20000

    Why it's wrong here

    Specifying a custom service object with port range 5060-20000 creates one continuous port span that includes dozens of unrelated ports, such as HTTP (80) or MySQL (3306), between the VoIP signaling and media ranges. This violates least-privilege firewall design and exposes the network to unnecessary traffic; a single FortiGate service object cannot represent two disjoint ranges. Therefore, you must use separate objects grouped together.

  • ✗

    Create two separate firewall policies, one for each port range

    Why it's wrong here

    Creating two separate firewall policies, one for SIP (5060) and one for RTP (10000-20000), technically works but doubles the rule count and creates a synchronization burden. Any future change to the action, source, or schedule must be applied to both policies, increasing the risk of policy drift and misconfiguration. A service group achieves the same result in a single policy, which is simpler and less error-prone.

  • ✗

    Use the predefined 'VoIP' service object

    Why it's wrong here

    The predefined 'VoIP' service object is a broad, version-dependent definition that typically bundles multiple VoIP signaling protocols (SIP, H.323, SCCP) and may not include the specific RTP media range or match your deployment's exact ports. Relying on it can either over-permit traffic for protocols you don't use or still require an additional rule for the media stream. For a controlled remote VoIP deployment, you need explicit service objects for SIP and RTP, not a generic predefined one.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.