NSE4 Firewall Policies and NAT Practice Question
An organization has multiple remote sites connected via IPsec VPN. The administrator needs to ensure that traffic from the internal network (10.0.0.0/8) to the VPN destination (10.10.0.0/16) uses a specific interface (port2) instead of the default route. Which feature should be configured?
⚠ Common exam trap
Test-takers frequently confuse policy-based routing with static route manipulation; candidates often think a static route with a higher distance can override the default route, but distance only affects route preference, not the ability to force traffic out a specific interface when a default route with lower distance exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy-based routing
Policy-based routing (PBR) allows you to override the default routing table by matching traffic based on source/destination addresses and directing it to a specific egress interface (port2). This is the correct feature because the requirement is to force traffic from 10.0.0.0/8 to 10.10.0.0/16 out port2, bypassing the default route.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Central NAT
Why it's wrong here
Central NAT rewrites source or destination IP addresses and ports during session setup, but it never influences the routing decision itself. In FortiOS, NAT is applied after the forwarding path has already selected an egress interface and next-hop based on the routing table. Therefore, while Central NAT can hide or translate addresses for IPSec traffic, it cannot direct traffic from specific remote sites to a different gateway or tunnel.
- ✗
Static route with higher distance
Why it's wrong here
A static route with a higher administrative distance is merely a backup path that is only consulted when the primary route is unavailable. Even when active, it selects the next-hop based solely on the destination IP address, not on the source address or other policy criteria. Because the requirement is to route traffic differently based on which remote site originated it, a static route cannot override the routing table in a source-aware manner.
- ✓
Policy-based routing
Why this is correct
Policy-based routing (PBR) in FortiOS lets you define a rule that matches specific criteria — such as source IP, source interface, protocol, or port — and then explicitly sets the output interface and next-hop gateway, overriding the routing table lookup. For an organization with multiple remote sites connected via IPSec, PBR can steer traffic from each site's subnet toward the appropriate VPN tunnel or local gateway. This is exactly the capability needed when destination-based routing alone would send all traffic over the same path.
- ✗
Traffic shaping
Why it's wrong here
Traffic shaping is a QoS mechanism that controls bandwidth allocation, packet priority, and queue scheduling, but it has no effect on the routing decision or next-hop selection. It can limit or prioritize traffic after the forwarding path has been determined, but it cannot change which egress interface or tunnel is used for a packet. Thus, traffic shaping would not solve a problem that requires source-based route selection.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.