Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator runs 'diagnose debug flow' for a specific source IP and sees the output includes 'no matching policy'. The FortiGate has a firewall policy that should match the traffic. What is the most likely reason for this message?

⚠ Common exam trap

NSE4 often tests the distinction between routing failures, policy lookup failures, and session-table exhaustion — candidates see 'no matching policy' and wrongly blame routing or security profiles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall policy is disabled or the source/destination interfaces do not match the traffic's ingress/egress interfaces

'No matching policy' in diagnose debug flow means the FortiGate evaluated the packet against the policy list and found no policy whose ingress interface, egress interface, source, destination, schedule, and service all matched. The most common causes are a disabled policy or an interface mismatch (traffic arriving on an interface the policy does not list as incoming).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiGate's routing table does not have a route for the destination

    Why it's wrong here

    In FortiGate's forwarding pipeline, route lookup happens before firewall policy lookup. If the routing table has no route for the destination, the debug flow output would show 'no matching route' or a similar routing error, not 'no matching policy'. Therefore this option cannot explain the observed message, because the packet would have failed earlier in the sequence.

  • ✓

    The firewall policy is disabled or the source/destination interfaces do not match the traffic's ingress/egress interfaces

    Why this is correct

    The debug flow output showing 'no matching policy' means the packet successfully completed route lookup and is now being matched against firewall policies. This error occurs when no enabled policy satisfies the traffic's characteristics, such as the ingress interface, egress interface, source/destination addresses, or destination port. A disabled policy is ignored entirely, and if the source or destination interfaces in a policy do not match the actual interfaces the traffic traverses, that policy will be skipped, leaving the traffic without a match.

  • ✗

    The security profiles applied to the policy are blocking the traffic

    Why it's wrong here

    Security profiles are only evaluated after a firewall policy has been matched, because each policy explicitly references which profiles to apply. If a profile were blocking the traffic, the debug flow would first show a successful policy match, then show the appropriate profile action such as 'block' or 'monitor', and only then drop the packet. The message 'no matching policy' by definition indicates the packet never passed the policy matching stage, so profile-based blocking cannot be the cause.

  • ✗

    The session table is full and cannot accept new sessions

    Why it's wrong here

    A full session table would cause new session creation to fail, but this failure occurs after a firewall policy has been matched and a session object is being allocated. The debug flow output would then show the policy match followed by a session table error, not the 'no matching policy' message. Since the policy lookup stage precedes session creation, a full session table has no bearing on whether a policy matches; it only affects whether a new session can be established after a match.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.