NSE4 Firewall Policies and NAT Practice Question
An administrator notices that VoIP traffic (SIP) is not being inspected by the IPS profile applied to the firewall policy. The administrator suspects the traffic is being accelerated by NPU offloading. Which TWO actions can prevent NPU offloading for SIP traffic to ensure IPS inspection? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse 'Deep Inspection' with a generic inspection mode, not realizing it is specific to SSL/TLS traffic and does not affect NPU offloading for SIP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the policy inspection mode to 'Proxy-Based'
Changing the inspection mode to 'Proxy-Based' forces the firewall to reassemble and inspect the entire SIP session in software, bypassing NPU offloading. NPU offloading accelerates traffic by processing packets in hardware, which skips deep inspection like IPS. Proxy-based inspection ensures the firewall acts as a proxy for the SIP traffic, allowing IPS to inspect the payload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change the policy inspection mode to 'Proxy-Based'
Why this is correct
Switching the policy inspection mode from Flow-Based to Proxy-Based forces all traffic in that policy to be processed by the FortiGate CPU rather than being offloaded to the CP/ASIC hardware. SIP ALG functionality, which handles call setup, NAT traversal, and opening pinholes for RTP media, is only fully executed when packets pass through the proxy engine. Because proxy-based inspection never offloads, this ensures the SIP ALG sees every packet, making it the most direct and reliable fix for SIP traffic not being inspected correctly.
- ✓
Disable 'Allow Offload' in the policy advanced options
Why this is correct
Disabling the 'Allow Offload' option in the policy's advanced settings prevents the matching sessions from being handed off to the Content Processor or ASIC for fast-path processing, even in Flow-Based mode. This forces the FortiGate to process the SIP traffic on the main CPU, where the SIP ALG can inspect and manage the session. This achieves the same effect as switching to Proxy-Based but only for this specific policy, preserving hardware acceleration for other traffic. It is a valid alternative when the administrator wants to minimize changes to the global inspection mode.
- ✗
Enable 'Set SNAT' on the policy
Why it's wrong here
Enabling 'Set SNAT' on the policy only changes the source IP/port of packets that already match the policy; it has no effect on whether the traffic is offloaded to hardware or inspected by the SIP ALG. Offloading decisions in FortiOS are based on the policy's inspection mode, protocol, and session state, not on NAT configuration. SNAT might even introduce additional complexities for SIP call flow, but it will not force SIP packets through the CPU, so the original issue of SIP not being properly inspected will persist.
- ✗
Enable 'Deep Inspection' on the policy
Why it's wrong here
Deep Inspection in FortiOS is specifically designed for SSL/TLS decryption and inspection of encrypted web traffic. SIP and SDP are plaintext protocols (usually over UDP 5060), so enabling Deep Inspection does not change how they are processed, nor does it affect the offload decision for non-SSL traffic. The SIP ALG would still be bypassed due to offloading, so this option does not resolve the problem. It would only add unnecessary overhead and require certificate validation, making it an incorrect and counterproductive choice here.
- ✗
Create a separate VIP for SIP
Why it's wrong here
Creating a separate VIP (Virtual IP) for SIP is intended for destination NAT or port forwarding, not for altering the forwarding path or inspection mode. A VIP maps an external address to an internal server, but the FortiGate still applies policy inspection and offload logic in the same way once traffic is matched. Since the offload of SIP traffic occurs before the VIP affects session handling, this change does nothing to force the SIP ALG to inspect the traffic. In fact, a separate VIP could complicate NAT for RTP unless the ALG is already actively involved, so it is both irrelevant and potentially harmful.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.