NSE4 Firewall Policies and NAT Practice Question
An administrator needs to configure a firewall policy to allow outbound traffic from the internal network to the internet. The internal network uses private IP addresses, and the FortiGate's WAN interface has a public IP. Which NAT configuration is appropriate to ensure return traffic is routed correctly?
⚠ Common exam trap
Candidates often confuse source NAT with destination NAT (VIP) or using a private IP pool for translation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable NAT in the firewall policy and use the outgoing interface address.
For outbound internet access from a private network, source NAT must be enabled in the firewall policy, typically using the outgoing interface address. This translates private IPs to the public IP of the WAN interface, allowing return traffic to reach the FortiGate and be forwarded back to the internal hosts. Other options either use incorrect NAT types or fail to translate to a routable address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable NAT and rely on the FortiGate's routing table to forward traffic.
Why it's wrong here
Disabling NAT would leave the private source IPs intact, which are not routable on the internet. Return traffic would not be able to reach the internal hosts because the public internet does not know how to route to private addresses. NAT is required for outbound internet access from private networks.
- ✗
Enable NAT and specify a custom IP pool with a private IP address.
Why it's wrong here
Using a private IP pool for NAT would not solve the routing issue because private IPs are not routable on the internet. The NAT pool must contain public IP addresses. Using a private IP pool would result in the same problem as no NAT, as return traffic would be unroutable.
- ✓
Enable NAT in the firewall policy and use the outgoing interface address.
Why this is correct
Enabling NAT in the policy and using the outgoing interface address translates the private source IPs to the public IP of the WAN interface. This is the standard configuration for outbound NAT (SNAT) and ensures that return traffic is sent back to the FortiGate, which then translates it back to the internal host. This meets the requirement.
- ✗
Create a VIP for the internal subnet and apply it as the source in the policy.
Why it's wrong here
A VIP is used for destination NAT, not source NAT. Applying a VIP as the source would not translate the private IPs to the public IP; it would attempt to match the source against the VIP, which is incorrect. VIPs are for publishing internal services to external networks.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.