Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An administrator runs 'diagnose firewall iprope list 100000' and sees 'action=deny' entries for traffic that should be allowed. The policy list shows an allow policy with ID 1 for that traffic. What is the most likely cause of the deny?

⚠ Common exam trap

Watch out — candidates often assume the policy list shown in the GUI or CLI always reflects the active kernel state, but Fortinet tests the understanding that a policy may exist in the configuration yet fail to install into the kernel, causing unexpected denies despite an apparent allow rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall policy is not installed in the kernel due to an error

The 'diagnose firewall iprope list 100000' command displays the kernel-level firewall policy list. If the policy list shows an allow policy (ID 1) but the kernel entries show 'action=deny', it indicates that the policy was not successfully installed into the kernel's connection tracking or firewall engine. This typically occurs due to a policy installation error, such as a configuration inconsistency or a failure during the commit process, causing the kernel to fall back to a default deny action for that traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The traffic is being blocked by a local-in policy

    Why it's wrong here

    Local-in policies govern traffic destined to the FortiGate's own interfaces, not forwarded traffic between interfaces. The 'diagnose firewall iprope list' command inspects the kernel's IPv4/IPv6 policy chain for transit traffic, so a local-in block would not be visible or relevant in that output. Moreover, a local-in policy drop would have already occurred before the session reaches the forwarding path, and would not cause an entry to be missing from the iprope list.

  • ✗

    The implicit deny rule is being triggered because the policy is disabled

    Why it's wrong here

    The implicit deny rule is always present in the kernel's policy chain as the final catch-all entry. A disabled policy is simply not installed into the kernel, which means traffic may fall through to that implicit deny, but the iprope list will still show the deny rule itself. The absence of the expected policy entry—not the implicit deny being 'triggered'—is what the administrator would observe in the output.

  • ✓

    The firewall policy is not installed in the kernel due to an error

    Why this is correct

    The 'diagnose firewall iprope list' command displays the kernel's actual IPv4 firewall policy list. If a policy fails to install—due to memory constraints, commit errors, or conflicting objects—it will be absent from this output, causing traffic to fall through to the implicit deny rule. An error message in the command's output or a missing policy ID is the direct indicator of a kernel installation failure, making this the correct explanation.

  • ✗

    A security profile is dropping the traffic after the policy matches

    Why it's wrong here

    Security profiles such as antivirus, IPS, and web filtering are enforced during session inspection in user-space, after the kernel has already matched traffic to a firewall policy. If a security profile were dropping traffic, the policy would still be present in the iprope list because the kernel has already applied it. A profile drop therefore cannot explain why a policy is missing from the kernel policy chain.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.