Courseiva

NSE4 Firewall Policies and NAT Practice Question

An administrator needs to configure outbound NAT for 200 internal users using a single public IP (203.0.113.1). The public IP provides 2000 ports. Some applications require a deterministic source port range for logging. Which TWO NAT settings should be used?

⚠ Common exam trap

Test-takers frequently confuse 'Fixed Port Range' with static NAT or assume that session helpers (Option C) are needed for port allocation, when in fact session helpers are for application-layer gateway functions, not for deterministic port assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP Pool type: Overload

(IP Pool type: Overload) is correct because it enables Port Address Translation (PAT), allowing 200 internal users to share a single public IP (203.0.113.1) by multiplexing sessions across the 2000 available ports. Option E (Set 'Fixed Port Range' on the IP Pool) is correct because it assigns a deterministic source port range to each user, which is required for logging and auditing applications that expect consistent port mappings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IP Pool type: One-to-One

    Why it's wrong here

    An IP Pool of type One-to-One maps a single private source IP to a single public IP address, preserving the original source port without multiplexing. With 200 internal hosts and only one or few public IPs, one-to-one NAT would require a separate public IP for each host, so it is not suitable for scalable outbound internet access.

  • ✗

    Configure a VIP for the public IP

    Why it's wrong here

    A Virtual IP (VIP) is a destination NAT object that translates incoming traffic sent to a public address into the private address of an internal server. It does not rewrite the source IP of outbound sessions originating from 200 internal hosts, so it cannot provide outbound internet NAT; a source NAT IP pool is required instead.

  • ✗

    Enable session helper for application

    Why it's wrong here

    Session helpers are ALG (Application Layer Gateway) components used to inspect and rewrite control channels for protocols such as FTP, SIP, or H.323 so that dynamic secondary channels can traverse the firewall. Enabling a session helper does not change the source IP or port allocation of outbound NAT and cannot help 200 hosts share a single public IP.

  • ✓

    IP Pool type: Overload

    Why this is correct

    An Overload IP pool implements many-to-one source NAT by translating multiple private source IPs into one public IP and using unique source port numbers to keep sessions separate. This is the essential mechanism for allowing 200 internal hosts to reach the internet through a single public address, because the combined number of concurrent sessions can share the same destination port on that one public IP.

  • ✓

    Set 'Fixed Port Range' on the IP Pool

    Why this is correct

    With an Overload pool, enabling 'Fixed Port Range' lets you define a specific range of source ports that the FortiGate can use for translated sessions. This creates more predictable source-port behavior when hundreds of hosts share the same public IP, helps avoid port-range conflicts with other NAT or security rules, and allows administrators to align NAT ports with existing firewall policy or monitoring requirements.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.