NSE4 Firewall Policies and NAT Practice Question
An administrator wants to allow access to an internal web server from the internet using a public IP address 203.0.113.10. The internal server has IP 10.0.0.5. Which FortiGate feature should be configured to translate the destination IP?
⚠ Common exam trap
Many exam-takers confuse destination NAT (VIP) with source NAT (IP Pool or Central SNAT), leading candidates to select a source NAT option when the question explicitly asks for destination IP translation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Virtual IP (VIP)
A Virtual IP (VIP) is the correct feature because it performs destination NAT (DNAT), translating the public destination IP 203.0.113.10 to the internal server IP 10.0.0.5. This allows inbound traffic from the internet to reach the internal web server by rewriting the destination IP address in the packet header as it traverses the FortiGate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Virtual IP (VIP)
Why this is correct
A Virtual IP (VIP) is the correct object for destination NAT on FortiGate. It maps an external public IP address (and optionally a port) to a private, internal server IP, so inbound traffic destined for the public address is forwarded to the internal web server. The translation applies to the destination address of the packet, exactly what is required to expose an internal web server to the internet.
- ✗
Central SNAT
Why it's wrong here
Central SNAT is exclusively a source NAT mechanism. It rewrites the source IP address of outbound connections (typically from a private LAN address to a public or upstream address) so return traffic can be routed back. It does not touch the destination IP, so it cannot translate a public destination address to a private one for inbound access to an internal web server.
- ✗
Policy-based routing
Why it's wrong here
Policy-based routing (PBR) does not perform address translation at all. PBR selects the next-hop or egress interface for traffic based on a set of configured criteria (e.g., source, destination, protocol, or application), overriding the routing table lookup. Since it only affects the path a packet takes and never rewrites the destination IP, it cannot convert a public address to a private address for an inbound web request.
- ✗
IP Pool
Why it's wrong here
An IP Pool is a collection of source IP addresses used for source NAT (SNAT), typically in conjunction with Central SNAT or NAT policies. It defines the public addresses from which outbound source translations are drawn, but it has no role in modifying destination addresses. For inbound access to an internal web server, you need a destination NAT mechanism such as a Virtual IP, not an IP Pool.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.