Courseiva

NSE4 Firewall Policies and NAT Practice Question

An administrator needs to configure a firewall policy to allow outbound traffic from the internal network to the internet. The internal network uses private IP addresses, and the administrator wants to hide these addresses from the internet. Which NAT configuration should be applied to the policy?

⚠ Common exam trap

Candidates often confuse central NAT with policy-based NAT; central NAT is a separate feature and not needed for simple outbound NAT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NAT and use the outgoing interface address.

For outbound traffic from a private network to the internet, source NAT (SNAT) is required to translate private IP addresses to a public IP address. The most common and straightforward method on a FortiGate is to enable NAT on the firewall policy and use the outgoing interface address. This translates all internal addresses to the IP of the FortiGate's external interface, allowing return traffic to be routed back.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable NAT and rely on the FortiGate to route private IPs.

    Why it's wrong here

    Disabling NAT means the private source IP addresses would be sent to the internet. Most internet routers will drop packets with private source addresses (RFC 1918), so return traffic would not reach the internal hosts. NAT is required to translate private addresses to a public address for internet communication.

  • ✗

    Enable NAT and use a central NAT table with a specific IP pool.

    Why it's wrong here

    Central NAT is an alternative method that uses a separate NAT table, but it is not required for basic outbound NAT. It adds complexity and is typically used when you need more granular control or when policy-based NAT is not sufficient. For a simple outbound scenario, policy-based NAT with outgoing interface address is sufficient and easier to manage.

  • ✗

    Enable NAT and use a fixed port range for source translation.

    Why it's wrong here

    A fixed port range is used when you need to limit the number of source ports available for NAT, often for compliance or to avoid port exhaustion. It is not necessary for basic outbound NAT and can actually restrict the number of simultaneous connections. The standard approach is to use the outgoing interface address without port restrictions.

  • ✓

    Enable NAT and use the outgoing interface address.

    Why this is correct

    Enabling NAT on the policy and using the outgoing interface address translates the source IP of internal hosts to the IP address of the FortiGate's outgoing interface. This hides private addresses and allows return traffic to be routed back correctly. It is the standard configuration for outbound NAT (many-to-one or many-to-many depending on the pool).

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.