Courseiva

NSE4 Firewall Policies and NAT Practice Question

An administrator wants to allow access to an internal web server from the internet using a public IP address 203.0.113.10. The internal server has IP 10.0.0.5. Which FortiGate feature should be configured to translate the destination IP?

⚠ Common exam trap

Many exam-takers confuse destination NAT (VIP) with source NAT (IP Pool or Central SNAT), leading candidates to select a source NAT option when the question explicitly asks for destination IP translation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Virtual IP (VIP)

A Virtual IP (VIP) is the correct feature because it performs destination NAT (DNAT), translating the public destination IP 203.0.113.10 to the internal server IP 10.0.0.5. This allows inbound traffic from the internet to reach the internal web server by rewriting the destination IP address in the packet header as it traverses the FortiGate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Virtual IP (VIP)

    Why this is correct

    A Virtual IP (VIP) is the correct object for destination NAT on FortiGate. It maps an external public IP address (and optionally a port) to a private, internal server IP, so inbound traffic destined for the public address is forwarded to the internal web server. The translation applies to the destination address of the packet, exactly what is required to expose an internal web server to the internet.

  • ✗

    Central SNAT

    Why it's wrong here

    Central SNAT is exclusively a source NAT mechanism. It rewrites the source IP address of outbound connections (typically from a private LAN address to a public or upstream address) so return traffic can be routed back. It does not touch the destination IP, so it cannot translate a public destination address to a private one for inbound access to an internal web server.

  • ✗

    Policy-based routing

    Why it's wrong here

    Policy-based routing (PBR) does not perform address translation at all. PBR selects the next-hop or egress interface for traffic based on a set of configured criteria (e.g., source, destination, protocol, or application), overriding the routing table lookup. Since it only affects the path a packet takes and never rewrites the destination IP, it cannot convert a public address to a private address for an inbound web request.

  • ✗

    IP Pool

    Why it's wrong here

    An IP Pool is a collection of source IP addresses used for source NAT (SNAT), typically in conjunction with Central SNAT or NAT policies. It defines the public addresses from which outbound source translations are drawn, but it has no role in modifying destination addresses. For inbound access to an internal web server, you need a destination NAT mechanism such as a Virtual IP, not an IP Pool.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.