Courseiva

CCNA Firewall Policies and NAT Questions

75 of 193 questions · Page 2/3 · Firewall Policies and NAT · Answers revealed

76
MCQeasy

A FortiGate administrator wants to ensure that traffic from the internal network to the internet is translated to a single public IP address. Which NAT method should be used?

A.Central SNAT
B.One-to-one NAT
C.Fixed port range NAT
D.Overload NAT
AnswerD

Overload NAT, also known as Port Address Translation (PAT), is the correct method for this scenario. It translates the source IP address of all internal hosts to one public IP while dynamically assigning a unique source port for each connection, preserving the host identity through the port mapping. This provides scalable, concurrent internet access for many internal users using a single public address.

Why this answer

Overload NAT (also known as Port Address Translation or PAT) is the correct method because it allows multiple internal hosts to share a single public IP address by mapping each session to a unique source port. This is exactly what the administrator needs: translating all internal-to-internet traffic to one public IP.

Exam trap

The trap here is that candidates often confuse 'Central SNAT' (a FortiGate configuration method) with a specific NAT type, or think 'one-to-one NAT' is suitable for sharing a single IP, when it actually requires a dedicated public IP per internal host.

How to eliminate wrong answers

Option A is wrong because Central SNAT is a policy-based NAT method in FortiGate that can use overload or other modes, but it is not a specific NAT method itself; it is a configuration approach. Option B is wrong because one-to-one NAT maps a single private IP to a single public IP, which would require multiple public IPs for multiple internal hosts, not a single public IP. Option C is wrong because fixed port range NAT allocates a fixed range of ports per internal host, which still requires multiple public IPs or port ranges and does not achieve the goal of using a single public IP for all traffic.

77
MCQmedium

An administrator wants to limit the bandwidth for a specific application (e.g., YouTube) across all users. The administrator creates a traffic shaper and applies it to the firewall policy. What additional configuration is needed to identify YouTube traffic?

A.Enable deep inspection and create a URL filter
B.Create a custom service object for YouTube
C.Use a geography object to block non-local traffic
D.Apply an Application Control profile to the policy
AnswerD

Applying an Application Control profile to the FortiGate policy identifies traffic by application signatures rather than by IP, protocol, or country. Once YouTube is identified, you can attach a traffic shaper to that policy (or use per-application bandwidth limits in the profile) to enforce a maximum bandwidth. This is the correct method because it targets the application while allowing other traffic to remain unaffected.

Why this answer

Application Control profiles are specifically designed to identify and control traffic based on application signatures, such as YouTube. A traffic shaper limits bandwidth, but it requires an Application Control profile to classify the traffic as YouTube before the shaping can be applied. Without this profile, the firewall cannot distinguish YouTube from other web traffic.

Exam trap

The trap here is that candidates often confuse URL filtering (which identifies web domains) with Application Control (which identifies applications by their network behavior), leading them to choose deep inspection and URL filtering instead of the correct Application Control profile.

How to eliminate wrong answers

Option A is wrong because deep inspection and URL filtering inspect HTTPS URLs and content, but they do not identify application traffic like YouTube by its network signatures; URL filtering can block or allow based on domain, but it cannot apply bandwidth shaping to a specific application within a policy. Option B is wrong because a custom service object defines protocols and ports (e.g., TCP/443), but YouTube uses standard HTTPS ports and cannot be uniquely identified by port alone; application identification requires deep packet inspection beyond layer 4. Option C is wrong because geography objects filter traffic based on source or destination IP geolocation, which is unrelated to identifying a specific application like YouTube; this would block or allow entire regions, not shape bandwidth for an application.

78
MCQhard

An admin configures a Central SNAT rule to translate internal 192.168.1.0/24 to 203.0.113.10 when accessing the internet. However, traffic from 192.168.1.100 to 8.8.8.8 shows source IP 192.168.1.100 in logs. What is the MOST likely cause?

A.The Central SNAT rule is disabled
B.The Central SNAT rule is applied to the wrong outgoing interface
C.The firewall policy has an IP pool configured, overriding Central SNAT
D.The destination address in the Central SNAT rule is incorrect
AnswerB

Central SNAT rules specify an outgoing interface, and if the interface does not match the actual egress interface used by the traffic, the rule is skipped and no translation occurs. However, in a typical policy-based NAT deployment, the firewall policy's IP pool takes precedence over any central SNAT rule, regardless of interface matching. This makes an interface mismatch a possible but less likely explanation, because the override would still mask the central rule even if the interface were correct.

Why this answer

The Central SNAT rule is not being applied to the traffic. The most likely cause is that the rule specifies an outgoing interface different from the one used to reach 8.8.8.8, so the rule does not match and no source translation occurs.

Exam trap

Candidates may confuse IP pool override with Central SNAT, but if an IP pool were active, the source would be changed to the pool IP. Here, the source remains the original internal IP, indicating the Central SNAT rule itself is not matching.

How to eliminate wrong answers

Option A is wrong because if the Central SNAT rule were disabled, no SNAT translation would occur, but the traffic would still be logged with the original source IP; however, the question states the admin configured the rule, and a disabled rule would not cause the observed behavior unless explicitly verified. Option B is wrong because Central SNAT rules are not interface-specific; they are applied globally based on source/destination criteria, so applying to the wrong outgoing interface would not cause the rule to be ignored entirely—it would simply not match the traffic. Option D is wrong because the destination address in the Central SNAT rule is used to match traffic (e.g., to the internet), and an incorrect destination would prevent the rule from matching, but the traffic would still be subject to other SNAT mechanisms like IP pools on the policy; the question specifically describes a scenario where the rule is configured but overridden, not a mismatch.

79
MCQmedium

A company has a web server in the DMZ that must be accessible from the internet on both HTTP and HTTPS. The admin configures a VIP to map the public IP to the server's private IP. However, external users can only reach HTTP. What is the MOST likely cause?

A.The VIP is configured for port forwarding only for HTTP (port 80)
B.The web server is not listening on HTTPS
C.The VIP is using overload mode instead of one-to-one
D.The firewall policy allowing traffic to the VIP only permits HTTP
AnswerA

The virtual IP (VIP) object on a FortiGate is responsible for destination NAT, mapping an external address and port to an internal server. When a VIP is defined with only the HTTP service (port 80), the FortiGate will only translate traffic destined to that external IP:port pair. Incoming HTTPS connections to port 443 are not matched by the VIP, so they are dropped or not forwarded, precisely matching the symptom that external users cannot reach the web server over HTTPS.

Why this answer

The VIP (Virtual IP) configuration on a FortiGate maps a public IP and port to a private IP and port. If the VIP is configured only for port forwarding on TCP 80 (HTTP), it will not translate traffic for TCP 443 (HTTPS). This is the most likely cause because external users can reach HTTP but not HTTPS, indicating the VIP itself is not handling HTTPS traffic.

Exam trap

The trap here is that candidates often assume the firewall policy is the issue, but the VIP itself must be configured to forward the specific ports; a policy allowing all traffic is useless if the VIP does not translate the destination port for HTTPS.

How to eliminate wrong answers

Option B is wrong because if the web server were not listening on HTTPS, the connection would still be attempted and fail at the server level, but the symptom is that external users cannot reach HTTPS at all, which points to a VIP or policy issue, not server configuration. Option C is wrong because overload mode (PAT) and one-to-one mode (DNAT) both can handle multiple ports; the mode does not restrict which ports are forwarded. Option D is wrong because the firewall policy allowing traffic to the VIP only permits HTTP would block HTTPS, but the question states the VIP is configured for port forwarding only for HTTP, making the VIP itself the root cause; a policy issue would be secondary and less likely given the VIP configuration.

80
MCQmedium

A network admin has configured a firewall policy allowing traffic from the 'internal' zone to the 'external' zone. The policy uses a service object 'HTTP' (TCP/80). Users report they can access HTTP websites but not HTTPS. The admin confirms no other policies block HTTPS. What is the most likely cause?

A.The FortiGate needs to perform SSL inspection on HTTPS traffic
B.There is a policy ordering issue; a later policy might block HTTPS
C.HTTPS traffic is being dropped by implicit deny because no policy matches it
D.The service object 'HTTP' also includes TCP/443 by default
AnswerC

This is the correct explanation. In FortiOS, every firewall policy list ends with an implicit deny rule that silently drops any traffic that does not match an explicit allow policy. The administrator's policy only allows the HTTP service (TCP/80), so HTTPS traffic (TCP/443) has no matching allow entry and is consequently dropped by the implicit deny rule. This is a classic failure point when administrators assume that allowing HTTP also covers HTTPS, or forget to add a separate policy for HTTPS.

Why this answer

The firewall policy explicitly allows only HTTP (TCP/80) traffic from the internal zone to the external zone. HTTPS uses TCP/443, which is not included in the service object 'HTTP'. Since no other policy permits HTTPS, the traffic hits the implicit deny rule at the end of the policy list, which drops all unmatched traffic.

This is the default behavior on FortiGate firewalls.

Exam trap

The trap here is that candidates assume a policy allowing HTTP will also allow HTTPS because both are web traffic, but FortiGate treats them as distinct services based on TCP port numbers, and implicit deny will block any unmatched traffic.

How to eliminate wrong answers

Option A is wrong because SSL inspection is not required for HTTPS traffic to pass through a firewall; it is only needed for deep packet inspection or decryption, not for basic connectivity. Option B is wrong because the admin confirmed no other policies block HTTPS, and a later policy would only block traffic if it explicitly denied it; the issue is that no policy permits HTTPS at all. Option D is wrong because the service object 'HTTP' is predefined as TCP/80 only and does not include TCP/443 by default; TCP/443 is part of the 'HTTPS' service object.

81
MCQmedium

An admin wants to apply different QoS markings to traffic from two different departments. The admin creates two firewall policies: one for Sales (policy ID 1) and one for Engineering (policy ID 2). Both policies have traffic shaping enabled. However, traffic from both departments receives the same QoS marking. What is the MOST likely mistake?

A.The policies are in the wrong order
B.QoS marking is only applied at the interface level
C.The traffic shaping policy is applied globally
D.The admin applied the same traffic shaper to both policies
AnswerD

When both firewall policies reference the identical traffic-shaper object, the QoS markings and bandwidth parameters applied by that shaper are the same for every matching session. To apply different QoS markings, the administrator must create at least two distinct traffic shapers, or configure separate diffserv/ToS values, and attach the appropriate shaper to each policy. If the shaper is the same in both rules, no amount of policy reordering or interface tweaking will produce separate markings. The correct solution is to give each traffic class its own shaper object so bandwidth allocation and diffserv markings can differ.

Why this answer

If the same traffic shaper is applied to both firewall policies, the QoS marking defined in that shaper will be identical for all matched traffic, regardless of the policy. Each policy must reference a distinct traffic shaper with the desired DSCP or 802.1p marking to differentiate the departments.

Exam trap

The trap here is that candidates assume creating separate firewall policies automatically results in different QoS markings, but they overlook that the traffic shaper itself must be unique and configured with the correct DSCP value for each policy.

How to eliminate wrong answers

Option A is wrong because policy order affects which policy matches first, but both policies are already matching traffic from different departments (Sales and Engineering), so order does not cause identical QoS markings. Option B is wrong because QoS marking in FortiOS can be applied at the firewall policy level via traffic shapers, not only at the interface level; interface-level QoS is for egress queuing, not marking. Option C is wrong because a global traffic shaping policy would apply to all traffic, but the question states both policies have traffic shaping enabled, implying per-policy shapers are used, not a global one.

82
MCQmedium

A network admin configures a firewall policy allowing HTTP traffic from internal users to an external web server. The policy uses a service object 'HTTP' defined as TCP/80. However, users cannot reach the server. What is the MOST likely cause?

A.The external web server is using HTTPS (TCP/443) instead of HTTP
B.The source address object does not include the users' subnet
C.The policy order is wrong; the policy is placed after a deny-all policy
D.The interface is set to the wrong zone
AnswerA

The service object in this policy explicitly allows only TCP port 80 (HTTP). An external web server listening on TCP/443 (HTTPS) will not match this policy; FortiGate implicitly denies all traffic that does not match any explicit policy, so the client's HTTPS request is silently dropped. To permit the traffic, the admin must either change the service object to HTTPS (TCP/443) or create a separate policy with the correct service.

Why this answer

The firewall policy explicitly allows TCP/80 (HTTP), but the external web server is using TCP/443 (HTTPS). Since the service object does not match the actual traffic, the firewall will drop or reject the packets, preventing connectivity. This is a classic service mismatch issue in FortiGate firewall policies.

Exam trap

The trap here is that candidates assume HTTP traffic is always on port 80, but the question deliberately sets up a scenario where the server uses HTTPS (port 443), testing the understanding that firewall policies are port-specific and service objects must match the actual application protocol.

How to eliminate wrong answers

Option B is wrong because the source address object not including the users' subnet would cause a different symptom—traffic from those users would not match the policy at all, but the question states the policy is configured for internal users, implying the source is correct. Option C is wrong because if the policy were placed after a deny-all policy, the traffic would be blocked by the deny-all rule, but the question does not indicate any policy order issue; the problem is specifically about service mismatch. Option D is wrong because an interface set to the wrong zone would prevent the policy from being matched due to zone mismatch, but the question focuses on the service definition, not interface/zone configuration.

83
MCQmedium

An administrator creates a firewall policy to allow outbound HTTP and HTTPS traffic from the internal network to the internet. The policy uses a dynamic IP pool for SNAT. Users report that some websites load slowly or fail to load intermittently. The administrator checks the firewall logs and sees 'session helper' warnings. What is the most likely cause?

A.The policy has traffic shaping enabled that is throttling the bandwidth
B.The firewall policy is configured for proxy-based inspection, causing high latency
C.The IP pool is configured with fixed port range, limiting the number of available ports
D.The DNS server on the internal network is misconfigured
AnswerC

A fixed port range in an IP pool restricts the translated source ports to a narrow set, such as 1024–2048, drastically capping the number of concurrent NAT sessions per pool address. Once those ports are exhausted, new outbound connections fail intermittently until old sessions time out, exactly matching the reported symptoms. Session helper warnings, such as for FTP or ICMP, appear because the helper cannot allocate a NAT port for the associated data channel, confirming that the IP pool port configuration is the root cause.

Why this answer

The 'session helper' warnings indicate that the firewall is struggling to allocate NAT sessions for the dynamic IP pool. When the IP pool uses a fixed port range, the number of available source ports per IP is limited, leading to port exhaustion under heavy HTTP/HTTPS traffic. This causes intermittent failures and slow loads as new connections are dropped or queued.

Exam trap

The trap here is that candidates confuse 'session helper' warnings with application-layer issues (like proxy latency or DNS) instead of recognizing it as a NAT resource exhaustion symptom tied to port range limitations in the IP pool configuration.

How to eliminate wrong answers

Option A is wrong because traffic shaping throttles bandwidth but does not generate 'session helper' warnings; those are related to NAT resource exhaustion, not rate limiting. Option B is wrong because proxy-based inspection can add latency but would not cause intermittent failures tied to port availability; 'session helper' warnings are specific to NAT session allocation, not inspection mode. Option D is wrong because a misconfigured DNS server would cause consistent name resolution failures, not intermittent loading issues with 'session helper' warnings in the firewall logs.

84
Matchingmedium

Match each Fortinet product to its primary role.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Next-generation firewall

Security information and event management

Centralized logging and analytics

Centralized management and policy orchestration

Advanced threat detection and analysis

Why these pairings

FortiGate is the NGFW, FortiManager handles centralized management, FortiAnalyzer provides logging/reporting, and FortiSandbox performs advanced threat detection. Common confusions include swapping management with firewall roles or logging with threat detection.

85
MCQeasy

Which address object type allows you to match traffic based on the domain name in the HTTPS SNI field?

A.Geography
B.Wildcard FQDN
C.Subnet
D.FQDN
AnswerB

A Wildcard FQDN object, such as *.example.com, matches domain names using a pattern and can be compared against the Server Name Indication (SNI) field in TLS handshakes. This allows FortiGate to filter traffic based on the domain name a client requests before the connection is decrypted. It is the only address object type among these options that natively supports SNI matching, making it the correct answer when domain-based traffic identification is needed.

Why this answer

The Wildcard FQDN address object type in FortiGate allows you to match traffic based on the domain name in the HTTPS Server Name Indication (SNI) field. Unlike a standard FQDN, which matches the exact domain, the Wildcard FQDN supports patterns like *.example.com, enabling policy enforcement for subdomains and dynamic hostnames within a domain.

Exam trap

The trap here is that candidates often confuse Wildcard FQDN with standard FQDN, assuming both can match subdomains, but only Wildcard FQDN supports the asterisk (*) wildcard for pattern matching in the SNI field.

How to eliminate wrong answers

Option A (Geography) is wrong because Geography objects match traffic based on the source or destination IP address's geolocation, not the domain name in the SNI field. Option C (Subnet) is wrong because Subnet objects match traffic based on IP address ranges, not domain names or SNI fields. Option D (FQDN) is wrong because a standard FQDN object matches the exact domain name in the SNI field but does not support wildcard patterns, making it unsuitable for matching subdomains or variable hostnames.

86
MCQeasy

What is the order of evaluation for firewall policies on a FortiGate?

A.Random order
B.From bottom to top
C.From top to bottom, first match
D.By policy ID in ascending order
AnswerC

FortiGate evaluates policies sequentially from the first entry in the policy table downwards, applying the first policy whose source, destination, service and schedule criteria match the packet; subsequent policies are never consulted once a match occurs.

Why this answer

FortiGate firewall policies are evaluated sequentially from the top of the policy list downward. The first policy that matches the traffic's source, destination, service, and schedule is applied, and no further policies are checked. This top-down, first-match behavior ensures deterministic traffic handling and is fundamental to FortiGate's policy-based architecture.

Exam trap

The trap here is that candidates often confuse policy ID with evaluation order, assuming policies are processed by ascending ID, but FortiGate evaluates based on the visual list order, which can be manually rearranged independently of the ID numbers.

How to eliminate wrong answers

Option A is wrong because FortiGate does not evaluate policies in random order; it uses a deterministic sequential evaluation from top to bottom. Option B is wrong because policies are evaluated from top to bottom, not bottom to top; a bottom-to-top order would reverse the intended priority and is not how FortiGate processes policies. Option D is wrong because while policy IDs are assigned sequentially, evaluation order is determined by the policy's position in the list (which can be rearranged), not by the numeric ID; reordering policies changes evaluation order independently of their IDs.

87
MCQeasy

A FortiGate policy allows traffic from the internal network to a DMZ server. The admin wants to limit access to only specific hours. Which object type should be used in the policy?

A.Address group
B.Schedule
C.Service group
D.Traffic shaper
AnswerB

Schedule is correct because FortiGate uses schedule objects (one-time or recurring) to define when a policy is permitted to match traffic. The policy's schedule field is evaluated during the lookup process; if the current time is outside the defined start/end and day-of-week parameters, the policy is skipped and traffic is compared against subsequent rules. This provides precise control over business hours, maintenance windows, or one-off events.

Why this answer

A schedule object is the correct choice because it defines time-based conditions (e.g., specific hours, days, or recurring intervals) that FortiGate applies to firewall policies. By attaching a schedule to a policy, the admin can restrict traffic to the DMZ server only during the permitted hours, such as business hours or maintenance windows.

Exam trap

The trap here is that candidates often confuse a schedule with a service group, thinking they can restrict time by limiting port availability, but FortiGate requires a dedicated schedule object for time-based policy enforcement.

How to eliminate wrong answers

Option A is wrong because an address group groups multiple IP addresses or subnets for source/destination matching, not time-based access control. Option C is wrong because a service group aggregates protocols and ports (e.g., TCP/80, UDP/53) for application filtering, not time restrictions. Option D is wrong because a traffic shaper controls bandwidth allocation and QoS, not temporal access limits.

88
MCQmedium

A company uses FSSO (Fortinet Single Sign-On) with a domain controller. Users authenticate to the domain, and the FortiGate retrieves the login events. The firewall policy uses the FSSO group. Some users report that after logging in, they cannot access resources that require authentication. The administrator checks the FSSO status and sees that the FortiGate is receiving login events. What is the most likely cause?

A.The user is not a member of the FSSO group
B.The FSSO collector agent is not running
C.The user's IP address is not in the source address range of the policy
D.The FortiGate is not polling the domain controller
AnswerC

FSSO authenticates the user and populates the group, but the firewall policy still matches on source address; if the workstation's IP falls outside that range, the policy never applies and traffic is denied. This satisfies the stem's symptom of successful login events yet blocked access.

Why this answer

Even though the FortiGate is receiving FSSO login events, the firewall policy also includes a source address restriction. If the user's IP address falls outside the defined source address range, the policy will not match, and the user will be denied access despite being authenticated via FSSO. The FSSO group membership is only one condition; the source IP must also satisfy the policy's source address criteria.

Exam trap

The trap here is that candidates assume receiving FSSO login events guarantees policy match, ignoring that the source address condition in the firewall policy is a separate, independent requirement that must also be satisfied.

How to eliminate wrong answers

Option A is wrong because if the user were not a member of the FSSO group, the FortiGate would not show the user as authenticated, and the administrator would not see the user's login events in the FSSO status. Option B is wrong because the FSSO collector agent is confirmed to be running since the FortiGate is receiving login events; a stopped collector agent would prevent event reception. Option D is wrong because the FortiGate is already receiving login events, which proves it is successfully polling or receiving data from the domain controller; if polling were failing, no events would appear.

89
MCQhard

An administrator has configured a firewall policy with a destination NAT (DNAT) VIP to map public IP 203.0.113.5 to internal server 10.10.10.20 on port 443. The policy allows HTTPS traffic from the internet to the VIP. However, when testing from an internal client on the same subnet as the server, the connection to 203.0.113.5 fails. What is the most likely cause?

A.Hairpin NAT (NAT loopback) is not configured, so internal clients cannot reach the public IP and be redirected to the internal server.
B.The firewall policy does not have NAT enabled for the outbound direction.
C.The firewall policy does not include the internal client's subnet as a source address.
D.The VIP does not have the 'port-forward' option enabled.
AnswerA

When an internal client tries to access the public IP of a VIP that points to an internal server on the same subnet, the traffic goes to the FortiGate, which performs DNAT, but the return traffic from the server goes directly to the client, bypassing the FortiGate. This asymmetric routing breaks the connection. Hairpin NAT (or NAT loopback) is required to ensure return traffic also goes through the FortiGate, allowing proper translation.

Why this answer

Hairpin NAT is required when internal clients access a public IP that is DNATed to an internal server. Without it, the server's return traffic bypasses the FortiGate, causing asymmetric routing and connection failure. Configuring hairpin NAT involves adding a firewall policy that allows the internal subnet to access the VIP and enabling NAT on that policy, ensuring return traffic is translated correctly.

Exam trap

The trap here is overlooking the need for hairpin NAT when internal clients access the public IP of a VIP that maps to an internal server.

90
Multi-Selecthard

A FortiGate administrator is configuring a policy-based routing (PBR) rule to send all traffic from the 'Engineering' VLAN (10.1.0.0/16) to a dedicated internet link through gateway 203.0.113.1. The administrator also wants to apply a traffic shaper to limit bandwidth. Which THREE configuration tasks must be performed?

Select 3 answers
A.Define a traffic shaper object with the desired bandwidth limits
B.Enable SD-WAN on the FortiGate
C.Configure Central NAT to translate the source IP
D.Create a policy-based route with source 10.1.0.0/16 and gateway 203.0.113.1
E.Create a firewall policy allowing traffic from Engineering VLAN to internet and apply the traffic shaper
AnswersA, D, E

The shaper must exist before it can be applied in a firewall policy.

Why this answer

A traffic shaper object must first be defined with the desired bandwidth limits (e.g., maximum rate, burst size) before it can be applied to a firewall policy. Without this object, the shaper cannot be referenced or enforced.

Exam trap

The trap here is that candidates often think SD-WAN is required for PBR or that Central NAT is mandatory, when in fact PBR and traffic shaping are independent features that can be configured without SD-WAN or Central NAT.

91
MCQmedium

A FortiGate has multiple firewall policies. Policy ID 1 allows HTTP from LAN to WAN. Policy ID 2 allows all traffic from DMZ to WAN. A packet arrives from the DMZ interface destined to a web server on the internet using HTTPS. Which policy is matched?

A.Policy ID 1, because it is first in order
B.Policy ID 2, but only if it has a service allowing HTTPS
C.Implicit deny, because no policy matches HTTPS traffic
D.Policy ID 2, because it matches the source interface and destination
AnswerD

Policy ID 2 is the correct match because it is the first policy whose source interface (DMZ) and destination interface (WAN) exactly correspond to the HTTPS traffic's ingress and egress. Its service is set to 'ALL', which encompasses HTTPS port 443, and its action is 'ACCEPT', meaning the firewall is explicitly configured to forward this session. Unlike Policy ID 1, which has mismatched interfaces, Policy ID 2 satisfies every required attribute for this traffic. Thus, it is the effective policy that permits the HTTPS traffic.

Why this answer

Policy ID 2 is matched because it allows all traffic from the DMZ interface to the WAN destination interface without any service restriction. The packet originates from the DMZ interface and is destined to the internet (WAN), so the source and destination interfaces match Policy ID 2. Since Policy ID 2 does not specify a service, it implicitly permits all protocols, including HTTPS.

Exam trap

The trap here is that candidates assume a policy must explicitly list a service (like HTTPS) to match HTTPS traffic, but FortiGate policies with no service defined match all traffic, and the order of policies only matters when multiple policies match the same source and destination interfaces.

How to eliminate wrong answers

Option A is wrong because Policy ID 1 specifies the source interface as LAN, not DMZ, so the packet from DMZ cannot match it regardless of order. Option B is wrong because Policy ID 2 allows all traffic without a service restriction, so it does not require an explicit HTTPS service to match. Option C is wrong because Policy ID 2 explicitly matches the source and destination interfaces and permits all traffic, so the implicit deny is not reached.

92
Multi-Selecthard

An administrator notices that VoIP traffic (SIP) is not being inspected by the IPS profile applied to the firewall policy. The administrator suspects the traffic is being accelerated by NPU offloading. Which TWO actions can prevent NPU offloading for SIP traffic to ensure IPS inspection? (Choose two.)

Select 2 answers
A.Change the policy inspection mode to 'Proxy-Based'
B.Disable 'Allow Offload' in the policy advanced options
C.Enable 'Set SNAT' on the policy
D.Enable 'Deep Inspection' on the policy
E.Create a separate VIP for SIP
AnswersA, B

Switching the policy inspection mode from Flow-Based to Proxy-Based forces all traffic in that policy to be processed by the FortiGate CPU rather than being offloaded to the CP/ASIC hardware. SIP ALG functionality, which handles call setup, NAT traversal, and opening pinholes for RTP media, is only fully executed when packets pass through the proxy engine. Because proxy-based inspection never offloads, this ensures the SIP ALG sees every packet, making it the most direct and reliable fix for SIP traffic not being inspected correctly.

Why this answer

Changing the inspection mode to 'Proxy-Based' forces the firewall to reassemble and inspect the entire SIP session in software, bypassing NPU offloading. NPU offloading accelerates traffic by processing packets in hardware, which skips deep inspection like IPS. Proxy-based inspection ensures the firewall acts as a proxy for the SIP traffic, allowing IPS to inspect the payload.

Exam trap

The trap here is that candidates often confuse 'Deep Inspection' with a generic inspection mode, not realizing it is specific to SSL/TLS traffic and does not affect NPU offloading for SIP.

93
Multi-Selecthard

An administrator needs to configure destination NAT for multiple internal servers using a single public IP address by differentiating based on destination port. The public IP 203.0.113.10 should map to: (A) 10.0.0.1:80 for HTTP, (B) 10.0.0.2:443 for HTTPS. Which TWO configuration steps are required? (Choose two.)

Select 2 answers
A.Create a VIP for HTTP mapping port 80 to 10.0.0.1
B.Create an IP pool for the public IP
C.Create a VIP for HTTPS mapping port 443 to 10.0.0.2
D.Configure policy-based routing for each server
E.Use Central SNAT with port forwarding
AnswersA, C

A Virtual IP (VIP) in FortiOS is the standard object for destination NAT, translating an incoming public IP:port pair to a private destination. By mapping the external address's TCP port 80 to 10.0.0.1:80, the administrator configures the DNAT rule that redirects inbound HTTP traffic to the first internal server. This VIP must then be referenced in a firewall policy that allows the traffic and performs the translation.

Why this answer

A Virtual IP (VIP) is required to map the public IP 203.0.113.10 and destination port 80 to the internal server 10.0.0.1:80. This is the standard FortiGate method for destination NAT (port forwarding) when multiple internal servers share a single public IP, differentiated by destination port.

Exam trap

The trap here is confusing IP pools (used for source NAT) with VIPs (used for destination NAT), leading candidates to incorrectly select IP pool or Central SNAT options for port forwarding scenarios.

94
MCQeasy

Which of the following is NOT a valid address object type in FortiGate?

A.Subnet
B.Wildcard FQDN
C.Geography
D.MAC address
AnswerD

MAC addresses are not a valid address object type in FortiGate firewall policies because policy matching is based on IP addresses, ports, and interfaces, not Layer 2 hardware addresses. While FortiOS can track MAC addresses for DHCP reservations, device inventory, and wireless user identification, those contexts use separate mechanisms rather than the address object list. Since the question asks for something that cannot be defined as a policy address object, MAC address is the correct choice.

Why this answer

FortiGate address objects support Subnet, Wildcard FQDN, and Geography types, but MAC addresses are not a valid address object type. MAC addresses are used in other contexts like static ARP entries or DHCP reservations, not as firewall address objects.

Exam trap

The trap here is that candidates may confuse MAC address filtering (available in some security features like device identification) with a valid firewall address object type, leading them to incorrectly select a wrong answer.

How to eliminate wrong answers

Option A is wrong because Subnet is a standard address object type in FortiGate, used to define IPv4 or IPv6 network ranges. Option B is wrong because Wildcard FQDN is a valid address object type that matches multiple FQDNs using wildcard patterns (e.g., *.example.com). Option C is wrong because Geography is a valid address object type that allows matching traffic based on source or destination country using GeoIP databases.

95
MCQmedium

An admin configures a firewall policy to allow SMTP traffic from a mail server to the internet with NAT enabled. External recipients report that the email source IP is the FortiGate's external interface IP. The admin wants the source to be a specific IP from a pool. What should the admin configure?

A.Create a central SNAT policy with the source as the mail server and the translated IP as the desired address
B.Use a VIP with port forwarding to translate the source
C.In the firewall policy, enable NAT and specify the IP pool as a fixed port range or overload
D.Enable NAT on the policy and set the IP pool configuration to use a dynamic IP pool
AnswerC

In the firewall policy, enabling NAT and referencing an IP pool is the proper method for policy-based source NAT. An IP pool configured as overload (PAT) allows multiple internal sessions to share a single translated IP, while a fixed port range pool also uses a single IP but constrains the source port range; both can satisfy the requirement for a single public address for the mail server. This is exactly what the admin needs for SMTP traffic, ensuring all outbound mail appears from the same IP. Thus it is the correct choice.

Why this answer

The admin wants the source IP of outbound SMTP traffic to be a specific IP from a pool rather than the FortiGate's external interface IP. In a firewall policy with NAT enabled, you can specify an IP pool to override the default source NAT behavior. The IP pool can be configured as Fixed Port Range or Overload (PAT) to translate the mail server's source IP to a desired address from the pool, ensuring external recipients see that specific IP.

Exam trap

The trap here is that candidates often confuse IP pools with VIPs or central SNAT, mistakenly thinking VIPs can modify source IPs or that central SNAT is required, when in fact the IP pool directly attached to the firewall policy is the correct and simplest solution for overriding the source NAT address.

How to eliminate wrong answers

Option A is wrong because a central SNAT policy is used for source NAT but does not allow specifying an IP pool directly within a firewall policy; it requires separate configuration and is not the standard method for overriding the translated IP in a policy-based NAT scenario. Option B is wrong because a Virtual IP (VIP) is used for destination NAT (port forwarding), not source NAT; it translates incoming traffic to an internal server, not outbound source IPs. Option D is wrong because a dynamic IP pool is used for load-balancing or rotating source IPs, not for pinning the source to a specific IP from a pool; the admin needs a fixed translation, which requires Fixed Port Range or Overload mode.

96
MCQmedium

An admin wants to ensure that VoIP traffic (UDP ports 5060-5061) from the internal network to the internet is prioritized over other traffic when the WAN link is congested. Which feature should be configured on the firewall policy?

A.Enable NAT on the policy
B.QoS marking only (DSCP)
C.Traffic shaping policy with a guaranteed bandwidth allocation and high priority
D.Configure a security profile with QoS settings
AnswerC

A traffic shaping policy is the only mechanism in FortiGate that can enforce both bandwidth reservations and queue priority for VoIP. By configuring a shaping profile with guaranteed bandwidth (e.g., 512 kbps) and setting priority to High, you instruct the traffic scheduler to service SIP/RTP UDP packets ahead of lower-priority flows and reserve capacity so that congestion does not starve voice. Guaranteed bandwidth ensures a minimum threshold, while high priority reduces jitter and latency, making this the correct choice for real-time traffic.

Why this answer

A traffic shaping policy with guaranteed bandwidth allocation and high priority ensures that VoIP traffic (UDP ports 5060-5061) receives the necessary bandwidth and is prioritized over other traffic during WAN congestion. Traffic shaping policies on FortiGate allow you to set guaranteed bandwidth, maximum bandwidth, and priority levels, which directly address congestion by reserving resources for critical traffic like VoIP.

Exam trap

The trap here is that candidates confuse DSCP marking (which only tags packets for external QoS) with local traffic shaping that actually enforces bandwidth guarantees and priority on the FortiGate itself, leading them to choose option B instead of C.

How to eliminate wrong answers

Option A is wrong because enabling NAT on the policy translates source IP addresses but does not provide any traffic prioritization or bandwidth guarantees during congestion. Option B is wrong because QoS marking only (DSCP) sets the Differentiated Services Code Point in the IP header for downstream devices, but on FortiGate, DSCP marking alone does not enforce local queuing or bandwidth allocation; it relies on downstream routers to honor the markings, which is insufficient for guaranteed prioritization on the WAN link. Option D is wrong because a security profile with QoS settings does not exist; security profiles (e.g., antivirus, web filtering) inspect content but do not manage bandwidth allocation or traffic priority, and QoS settings are configured separately in traffic shaping policies.

97
MCQhard

A FortiGate has a policy-based NAT rule that translates source IPs from subnet 192.168.1.0/24 to 203.0.113.10 when accessing the internet. The admin also enables Central SNAT with a rule that translates the same subnet to 203.0.113.20. If both are configured, which translation will be applied to traffic from 192.168.1.0/24 to the internet?

A.Both translations will be applied, causing an error
B.Central SNAT because it is a global setting
C.The FortiGate will use the translation from the policy with the highest ID
D.Policy-based NAT because it is evaluated first
AnswerD

FortiGate's NAT decision pipeline always evaluates policy-based NAT before Central NAT. When a session matches a firewall policy with an explicit NAT translation, that translation is applied immediately; Central SNAT rules are consulted only after no policy-based NAT rule matched. This design makes the more specific, policy-scoped translation authoritative, which is why traffic flows through the policy-based NAT rule.

Why this answer

Policy-based NAT is evaluated before Central SNAT because it is directly tied to the firewall policy that matches the traffic. When a policy-based NAT rule exists for the same traffic, it takes precedence over Central SNAT rules, regardless of any global settings or rule IDs. Therefore, the source IPs from 192.168.1.0/24 will be translated to 203.0.113.10.

Exam trap

The trap here is that candidates often assume Central SNAT, being a centralized feature, overrides all other NAT rules, but FortiGate explicitly gives policy-based NAT higher precedence for traffic matching a firewall policy.

How to eliminate wrong answers

Option A is wrong because FortiGate does not apply both translations simultaneously; it selects one based on precedence, and policy-based NAT is evaluated first, so no error occurs. Option B is wrong because Central SNAT is not a global setting that overrides policy-based NAT; policy-based NAT is tied to a specific firewall policy and takes precedence over Central SNAT for that matched traffic. Option C is wrong because the FortiGate does not use the policy ID to determine NAT precedence between policy-based NAT and Central SNAT; policy-based NAT is always evaluated first regardless of ID.

98
MCQhard

An admin configures a policy-based NAT rule (central SNAT) to translate source IPs from 10.0.0.0/24 to a dynamic IP pool of 203.0.113.1-203.0.113.10 with overload enabled. Users report that some connections are dropped. What is the MOST likely cause?

A.The port range for each IP in the pool is exhausted
B.The firewall policy has 'set nat enable' disabled
C.The route to the internet is missing
D.The pool does not have enough IPs to cover all users
AnswerA

With overload, each pool IP has a finite port range; once all ports on all ten addresses are consumed by concurrent sessions, new connections cannot be translated and are dropped. Exhaustion of that port range is the likely cause.

Why this answer

With overload enabled (Port Address Translation), the firewall translates multiple internal IPs to a single public IP by using unique source ports. Each public IP can handle up to 65,535 ports, but the actual usable port range is often smaller due to reserved ports and system limits. When all ports on all IPs in the pool are consumed, new connections are dropped because no port can be allocated for the translation.

Exam trap

The trap here is that candidates assume the pool must have enough IPs for each user, but overload (PAT) allows many users to share a single IP, so the real bottleneck is port exhaustion, not IP count.

How to eliminate wrong answers

Option B is wrong because 'set nat enable' is a legacy setting for policy-based NAT; central SNAT rules do not require this option to be enabled on the firewall policy. Option C is wrong because a missing internet route would cause all outbound traffic to fail, not just some connections being dropped. Option D is wrong because dynamic IP pools with overload do not require one IP per user; the issue is port exhaustion, not a lack of IP addresses.

99
MCQhard

An administrator uses 'diagnose sys session list' and sees the following output for a session: 'proto=6 proto_state=01 duration=3600 expire=3599'. The session is for HTTPS traffic. What does 'proto_state=01' typically indicate in FortiGate?

A.The session is being NATted
B.The session is fully established and active
C.The session is in the initial connection setup phase (SYN_SENT)
D.The session is being inspected by a security profile
AnswerC

The proto_state value 0x01 in the output of 'diagnose sys session list' corresponds to the TCP SYN_SENT state, which occurs during the initial connection setup phase. In this phase, the initiator has transmitted a SYN packet and is awaiting the peer's SYN-ACK response, meaning the three-way handshake is incomplete. This is precisely why the session is not fully established and why this is the correct answer.

Why this answer

In FortiGate, 'proto_state=01' for TCP (proto=6) indicates the session is in the SYN_SENT phase, meaning the initial SYN packet has been sent but the three-way handshake is not yet complete. For HTTPS traffic, this shows the session is still in the connection setup stage, not fully established. The 'duration' and 'expire' values reflect the time since the session was created and the remaining timeout, which is typical for an incomplete handshake.

Exam trap

The trap here is that candidates often confuse 'proto_state=01' with a fully established session because they see 'duration' and 'expire' values and assume the session is active, but the state code explicitly indicates the handshake is incomplete.

How to eliminate wrong answers

Option A is wrong because NAT status is indicated by the 'nat' field in the session list output, not by 'proto_state'; 'proto_state=01' is a TCP state code, not a NAT indicator. Option B is wrong because a fully established and active TCP session would show 'proto_state=02' (ESTABLISHED), not '01' (SYN_SENT). Option D is wrong because security profile inspection is shown by flags like 'ips', 'av', or 'app' in the session output, not by the TCP state field; 'proto_state' only reflects the TCP handshake phase.

100
MCQhard

A FortiGate administrator has configured a firewall policy with source NAT using an IP pool that contains two IP addresses: 203.0.113.10 and 203.0.113.11. The pool type is set to 'Overload'. The administrator notices that some outbound connections are failing, and when checking the session table, sees that many sessions are using the same source IP and port. What is the most likely cause of the connection failures?

A.The IP pool is configured with the wrong netmask, causing the FortiGate to incorrectly calculate the available addresses.
B.The FortiGate is running out of available source ports because too many sessions are being translated to the same IP address.
C.The IP pool is configured as 'Overload', which only allows one IP address to be used; the second IP is ignored.
D.The firewall policy is using the wrong outgoing interface, so the NAT pool is not being applied correctly.
AnswerB

This is correct because with an 'Overload' IP pool, multiple sessions can be mapped to the same IP address, but each session requires a unique source port. The FortiGate has a limited number of ports per IP (approximately 64,000). If the number of concurrent sessions exceeds the available ports, new connections will fail. The administrator should consider adding more IP addresses to the pool or using a different NAT type.

Why this answer

An 'Overload' IP pool allows multiple sessions to share the same IP address by using different source ports. However, each IP address has a finite number of ports (about 64,000). If the number of concurrent sessions exceeds this limit, new connections will fail because no ports are available.

The solution is to add more IP addresses to the pool or use a different NAT configuration. This is a common issue in environments with high session counts.

Exam trap

The trap here is assuming that an 'Overload' IP pool with multiple IPs will automatically distribute sessions evenly, when in fact it uses one IP until ports are exhausted before moving to the next.

101
MCQmedium

A FortiGate administrator has enabled central NAT (policy-based NAT) in the VDOM. They need to translate all outbound traffic from the internal subnet 192.168.1.0/24 to the FortiGate's WAN interface IP when it leaves the network. Where must the NAT configuration be referenced in the firewall policy?

A.Enable NAT in the firewall policy and select the central SNAT rule from the NAT dropdown.
B.Create an IP pool with the WAN IP and apply it as the NAT IP in the firewall policy, then disable central NAT.
C.Configure a virtual IP (VIP) for the internal subnet and reference it in the firewall policy as the source.
D.Create a central SNAT rule that matches the source subnet and outgoing interface, and ensure the firewall policy has no NAT configuration.
AnswerD

With central NAT enabled, SNAT is handled by central SNAT rules that are evaluated independently of firewall policies. The firewall policy itself must not have NAT enabled; it simply allows the traffic. The central SNAT rule matches source and destination criteria and performs the translation. This is the correct configuration for policy-based NAT in FortiOS.

Why this answer

When central NAT is enabled, the FortiGate uses central SNAT rules instead of per-policy NAT. The firewall policy references the central SNAT rule implicitly by matching traffic; the policy itself must not have NAT enabled. The central SNAT rule defines the source and destination criteria and the translation.

This separation simplifies management and avoids conflicting NAT configurations.

Exam trap

The trap here is assuming that NAT must still be enabled in the firewall policy even when central NAT is enabled, which is not the case.

102
MCQmedium

A network administrator has configured a firewall policy allowing traffic from the internal network (10.0.0.0/8) to the internet. Users report that some websites are not loading. The administrator runs 'diagnose firewall iprope list 100000' and sees the policy listed with a hit count of zero. What is the MOST likely cause?

A.The source interface or destination interface is incorrectly configured
B.The policy has a schedule that does not match the current time
C.The policy is placed below a more specific or broader policy that matches the same traffic
D.The FortiGate has a routing issue preventing traffic from reaching the internet
AnswerC

FortiGate firewall policies are evaluated top-down and the first policy that matches all configured criteria (source, destination, interface, and service) is executed; lower policies are never reached if a higher policy matches the same traffic. This means a broader policy placed above this specific rule—for example, an any-to-any policy—will shadow it, causing this rule's hit count to remain zero. Since FortiGate uses first-match rather than best-match, rule ordering is critical, and moving this rule above the broad policy would restore its visibility and hit count.

Why this answer

A hit count of zero indicates the firewall policy has never matched any traffic. When a more specific or broader policy exists above it in the sequence, the FortiGate processes policies top-down and stops at the first match, so the lower policy never gets evaluated. This is the most likely cause given that the policy is present but unused.

Exam trap

The trap here is that candidates often assume a zero hit count means the policy is not working due to misconfiguration or routing, but the real issue is policy ordering and the top-down match-first behavior of FortiGate firewalls.

How to eliminate wrong answers

Option A is wrong because if the source or destination interface were misconfigured, the traffic would not match any policy at all, but the administrator would likely see hits on other policies or no hits anywhere, not specifically zero on this policy while other policies may have hits. Option B is wrong because a schedule mismatch would prevent the policy from being active, but the policy would still appear in the rule list with a hit count of zero; however, the question states users can reach some websites, implying some traffic is passing, which would not be the case if a schedule were blocking all traffic through this policy. Option D is wrong because a routing issue would prevent traffic from reaching the internet entirely, but users report only some websites are not loading, indicating partial connectivity, and routing issues would affect all internet-bound traffic, not just specific sites.

103
Multi-Selectmedium

An administrator is configuring a firewall policy to allow web traffic from the internal network to the internet. They want to apply security profiles and ensure that only HTTP and HTTPS are allowed. Which two actions are required in the firewall policy configuration? (Choose two.)

Select 2 answers
A.Enable NAT in the policy to translate internal IPs to the outgoing interface address.
B.Attach at least one security profile, such as an antivirus or web filter profile.
C.Set the service to HTTP and HTTPS.
D.Attach an application control profile to the policy.
E.Enable logging of all sessions.
AnswersB, C

The administrator wants to apply security profiles. At a minimum, attaching one security profile (e.g., antivirus, web filter, IPS) is necessary to meet that requirement. This ensures that the traffic is inspected and protected according to the organization's security policy. This is a required action.

Why this answer

To allow only HTTP and HTTPS with security profiles, the policy must specify those services and have at least one security profile attached. These two actions ensure the traffic is limited to web protocols and inspected. NAT and logging are optional depending on network design and policy, and application control is a specific profile that may not be required.

Exam trap

The trap here is assuming that NAT or logging are mandatory for a functional outbound web policy, when they are not required to meet the stated goals.

104
MCQeasy

An admin wants to allow traffic only from specific countries to access a web server. Which type of address object should be used in the firewall policy?

A.Subnet object
B.Geography object
C.FQDN object
D.Wildcard FQDN object
AnswerB

A geography object in FortiGate is the correct mechanism for country-based access control. It references entries in the built-in geolocation database that classifies IP addresses by country, and when used as a source address in a firewall policy, FortiGate extracts the source IP's country and matches it against the object. This enables the admin to create a policy whose source is a specific country object, thereby restricting traffic to that geographic origin.

Why this answer

The Geography object (also known as a GeoIP object) in FortiGate allows firewall policies to permit or deny traffic based on the source or destination country. This is the correct choice because the requirement is to filter traffic by country, which is exactly what Geography objects are designed for, using IP-to-country mappings maintained by FortiGuard.

Exam trap

The trap here is that candidates may confuse Geography objects with FQDN or Subnet objects, thinking they can achieve country filtering by manually listing IP ranges, but FortiGate's GeoIP feature is the only efficient and accurate method for country-based policies.

How to eliminate wrong answers

Option A is wrong because a Subnet object defines a specific IP address range (e.g., 192.168.1.0/24) and cannot represent an entire country's IP space, which is dynamic and not a single contiguous subnet. Option C is wrong because an FQDN object resolves a fully qualified domain name to IP addresses, but it does not provide country-level filtering; it is used for policies based on domain names. Option D is wrong because a Wildcard FQDN object matches multiple subdomains (e.g., *.example.com) and is unrelated to geographic location filtering.

105
MCQeasy

An admin needs to translate the source IP of traffic from multiple internal hosts to a single public IP when accessing the internet, while keeping track of each session. Which NAT method should be used?

A.Fixed port range NAT
B.One-to-one NAT
C.Central SNAT without overload
D.Overload NAT (Port Address Translation)
AnswerD

Overload NAT, also known as Port Address Translation (PAT), allows many internal hosts to share one public IP by rewriting not only the source IP but also the source port to a unique, dynamically assigned value. The NAT engine maintains a translation table keyed by the public IP and the new source port, so return traffic is correctly forwarded back to the original internal host. This session multiplexing is what makes a single public IP sufficient for the entire internal network, with a theoretical maximum of about 65,536 concurrent sessions per public IP.

Why this answer

Overload NAT, also known as Port Address Translation (PAT), allows multiple internal hosts to share a single public IP address by mapping each session to a unique source port. This is the correct method for translating source IPs from multiple internal hosts to one public IP while maintaining session tracking, as it uses the transport-layer port number to differentiate between concurrent connections.

Exam trap

The trap here is that candidates often confuse 'Central SNAT without overload' with PAT, not realizing that without overload (port translation), the NAT device cannot multiplex multiple internal hosts to a single public IP, leading to session failures.

How to eliminate wrong answers

Option A is wrong because Fixed port range NAT assigns a predefined range of ports to each internal host, which limits the number of concurrent sessions per host and does not efficiently share a single public IP across many hosts. Option B is wrong because One-to-one NAT maps a single internal IP to a single external IP, requiring a public IP for each internal host, which does not conserve public IP addresses. Option C is wrong because Central SNAT without overload translates the source IP without using port multiplexing, meaning it can only handle one session per public IP at a time, causing conflicts when multiple internal hosts try to access the internet simultaneously.

106
Multi-Selectmedium

An administrator is troubleshooting why traffic from a specific subnet (192.168.10.0/24) to the internet is not being matched by the expected firewall policy. The policy list shows an allow policy for this traffic at ID 10, but there is a deny policy at ID 5 for any traffic from 192.168.0.0/16. Which TWO statements are correct?

Select 2 answers
A.The deny policy at ID 5 is matching the traffic before the allow policy at ID 10
B.The allow policy at ID 10 will override the deny policy because it is more specific
C.The traffic will be matched by the implicit deny at the end of the policy list
D.The administrator should enable 'policy override' on the allow policy
E.The administrator should change the deny policy's source to exclude 192.168.10.0/24 or move the allow policy above ID 5
AnswersA, E

Because FortiGate evaluates firewall policies in ascending order of policy ID, the deny at ID 5 is checked before the allow at ID 10. The source 192.168.10.0/24 is entirely within the broader 192.168.0.0/16 object used by the deny policy, so the traffic satisfies all matching criteria of ID 5 and is denied immediately, never reaching ID 10.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom based on their policy ID. Since policy ID 5 (deny for 192.168.0.0/16) appears before policy ID 10 (allow for 192.168.10.0/24), traffic from 192.168.10.0/24 is matched by the broader deny policy first, and the allow policy is never reached. This is a fundamental behavior of FortiGate's policy lookup order.

Exam trap

The trap here is that candidates often assume firewall policies use a 'most specific match' logic like routing, but FortiGate strictly uses sequential first-match based on policy ID order.

107
MCQmedium

A FortiGate administrator has configured a firewall policy allowing HTTP traffic from the internal network (10.0.1.0/24) to the DMZ server (192.168.1.10). The policy is placed after a deny-all policy that blocks traffic from internal to DMZ. Even though the allow policy is more specific, traffic is still being denied. What is the most likely cause?

A.The deny-all policy has a higher policy ID than the allow policy
B.The allow policy is configured with the wrong source interface
C.The allow policy uses a schedule that is not active at the current time
D.The deny-all policy is placed above the allow policy in the policy list
AnswerD

FortiOS performs first-match evaluation, checking rules top-down and enforcing the first rule whose all conditions (source, destination, service, schedule, etc.) are satisfied. If a broad deny-all is positioned above the specific allow policy, every packet that would otherwise match the allow rule hits the deny-all first and is dropped. That is the classic misordering mistake, and it cannot be compensated for by policy IDs or other attributes.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom. The first matching policy is applied, and subsequent policies are ignored. Since the deny-all policy is placed above the more specific allow policy, traffic from 10.0.1.0/24 to 192.168.1.10 matches the deny-all first and is dropped, never reaching the allow rule.

Exam trap

The trap here is that candidates mistakenly believe FortiGate uses a 'best-match' or 'most-specific' logic like routing tables, when in fact it uses strict first-match sequential evaluation, making policy order critical.

How to eliminate wrong answers

Option A is wrong because policy ID order does not determine evaluation priority; FortiGate uses the physical sequence in the policy list, not the ID number. Option B is wrong because if the source interface were incorrect, the traffic would not match the allow policy at all, but the question states the traffic is denied by the deny-all policy, implying the allow policy is otherwise correctly configured. Option C is wrong because a schedule issue would cause the allow policy to be inactive, but the traffic would still be evaluated against the deny-all policy and denied; however, the most likely cause given the policy placement is the order, not a schedule.

108
Multi-Selecthard

An administrator is troubleshooting why traffic from a specific VLAN (192.168.10.0/24) to the internet is not being NATed correctly. The firewall policy allows the traffic with NAT enabled and uses an IP Pool (overload) for the source translation. The IP Pool is configured with the address 203.0.113.10. However, the traffic still shows the original source IP. Which THREE of the following could cause this issue? (Choose three.)

Select 3 answers
A.There is a Central SNAT rule with higher priority that does not match the traffic
B.The firewall policy does not have the IP Pool selected in the NAT section
C.The IP Pool is configured on the wrong outgoing interface
D.The IP Pool uses one-to-one NAT instead of overload
E.Another firewall policy above the current one matches the traffic and either denies it or does not use NAT
AnswersB, C, E

In FortiGate policy-based NAT, an IP Pool is only applied when the firewall policy explicitly references it via the 'NAT' section and the 'Use IP Pool' dropdown. Merely creating an IP Pool does not cause it to be used; the pool must be tied to the specific policy that binds the source and destination. Without that selection, the firewall falls back to using the outgoing interface address or no NAT, which would leave the original source IP visible.

Why this answer

The IP Pool must be explicitly selected in the NAT section of the firewall policy for the pool to be used for source translation. Without this selection, the firewall will use the default NAT behavior (typically the outgoing interface IP) or no NAT at all, even if NAT is enabled on the policy.

Exam trap

The trap here is that candidates often assume simply enabling NAT on the policy and configuring an IP Pool is sufficient, but they overlook the requirement to explicitly select the IP Pool in the policy's NAT settings.

109
MCQeasy

Which statement about the implicit deny policy on a FortiGate is true?

A.It is a user-configurable policy that can be deleted
B.It allows traffic that matches no other policy
C.It can be moved to a different position in the policy list
D.It is always at the bottom of the policy list and denies all unmatched traffic
AnswerD

This is the correct statement. In FortiOS, the implicit deny is always located at the very end of the policy list, after every user-created policy, and serves as the final catch-all rule. During sequential policy lookup, if no explicit policy matches the traffic parameters, the implicit deny matches all remaining sessions and blocks them by discarding the packets, thereby enforcing a strict default-deny posture.

Why this answer

The implicit deny policy is a built-in, non-configurable security policy that resides at the very bottom of the FortiGate policy list. It automatically denies all traffic that does not match any explicit user-defined policy, ensuring that only explicitly permitted traffic is allowed through the firewall.

Exam trap

The trap here is that candidates often think the implicit deny can be modified or moved, confusing it with a regular policy, but FortiGate enforces it as an unchangeable last-resort rule that cannot be deleted, reordered, or altered.

How to eliminate wrong answers

Option A is wrong because the implicit deny policy is not user-configurable and cannot be deleted; it is a hardcoded default rule. Option B is wrong because the implicit deny policy denies, not allows, traffic that matches no other policy. Option C is wrong because the implicit deny policy is fixed at the bottom of the policy list and cannot be moved to a different position.

110
Multi-Selecthard

An admin is configuring a policy-based NAT (central SNAT) to translate internal users to a pool of public IPs using overload. The admin wants to ensure that specific applications using non-standard ports are not affected by NAT. Which THREE steps should the admin consider?

Select 3 answers
A.Disable NAT for those applications by adding a policy before the NAT policy with 'set nat disable'
B.Configure a separate IP pool dedicated to those applications
C.Use a fixed port range in the IP pool configuration
D.Use central SNAT with a VIP for source NAT
E.Enable 'set nat enable' on the policy
AnswersA, B, C

Adding a policy before the central SNAT policy with 'set nat disable' creates a deterministic exception: traffic matching that earlier policy is evaluated and its NAT disabled, so it is never processed by the subsequent central SNAT rule. Due to FortiOS policy ordering, the first match wins, meaning this exempt policy must be placed ahead of the NAT policy. This selectively preserves the original source address/port for those applications while other traffic continues through central SNAT.

Why this answer

Adding a policy before the central SNAT policy with `set nat disable` explicitly exempts specific traffic from NAT translation, ensuring that applications using non-standard ports are not affected by the overload behavior. Option B is correct because configuring a separate IP pool dedicated to those applications allows you to control the NAT behavior independently, such as using a pool without PAT or with a fixed port range, thereby avoiding port remapping issues. Option C is correct because using a fixed port range in the IP pool confines source port allocation to a specified range, accommodating applications that expect particular ports.

Option D is incorrect because a VIP is for destination NAT, not source NAT, and does not address source port modification. Option E is incorrect because enabling NAT on the policy would translate all traffic, not protect specific applications.

Exam trap

The trap is that candidates may believe only disabling NAT (Option A) can protect applications, overlooking that a dedicated IP pool with a fixed port range (Options B and C) can also preserve application behavior by controlling source port allocation. Additionally, some might incorrectly assume that a VIP (Option D) or simply enabling NAT (Option E) would address the issue.

111
MCQmedium

A network admin runs 'diag sys session filter proto 6' and 'diag sys session list' and sees many sessions with state 'SYN_SENT' to a public web server. The firewall policy allows TCP/443. What is the MOST likely cause?

A.The web server is overloaded and dropping connections
B.The policy is in proxy mode but should be flow mode
C.The destination NAT (VIP) for the web server is not configured
D.The firewall policy has session TTL set too low
AnswerC

The destination NAT (VIP) is the critical missing element in this scenario. When a client sends a TCP SYN to the web server's public IP, the FortiGate must use a matching VIP to translate that destination to the server's private IP address; without it, the firewall has no next hop or internal server to forward the packet to. As a result, the SYN is dropped or consumed by the firewall itself, the server never receives the request, and the client's session stays in SYN_SENT.

Why this answer

The 'diag sys session filter proto 6' command filters for TCP sessions (protocol 6). Seeing many sessions stuck in 'SYN_SENT' state indicates that the FortiGate is sending SYN packets to the destination but never receiving a SYN-ACK reply. Since the firewall policy allows TCP/443, the most likely cause is that the destination NAT (VIP) for the public web server is not configured.

Without a VIP, the FortiGate forwards the packet with the original destination IP (the public IP), which may not be routable or may not exist on the internal network, causing the SYN to be sent into a black hole.

Exam trap

The trap here is that candidates assume 'SYN_SENT' always indicates a server-side issue (like overload or firewall blocking), but in FortiGate diagnostics, it specifically points to a missing or misconfigured destination NAT when the destination is a public IP that must be translated to an internal server.

How to eliminate wrong answers

Option A is wrong because an overloaded web server would typically respond with a SYN-ACK or RST, not cause the FortiGate to see endless 'SYN_SENT' states; the server would still complete the TCP handshake or reject the connection. Option B is wrong because proxy mode vs. flow mode affects how the firewall processes traffic (e.g., deep inspection), but it does not cause sessions to remain in 'SYN_SENT' state; that state indicates a failure in the TCP handshake at the network layer. Option D is wrong because a low session TTL would cause sessions to expire prematurely, not prevent the initial SYN-ACK from being received; 'SYN_SENT' means the handshake never completed, not that it was terminated early.

112
Multi-Selectmedium

A company has two internet connections (WAN1 and WAN2). The administrator wants to route HTTP traffic from the internal network through WAN1, and all other traffic through WAN2. Which TWO configurations are needed?

Select 2 answers
A.Define an SD-WAN rule that matches HTTP and sets WAN1 as preferred
B.Apply NAT with IP pool on the firewall policy
C.Add a static route with a lower priority to WAN1
D.Create a policy-based routing rule to send HTTP traffic to WAN1
E.Configure load balancing between WAN1 and WAN2
AnswersA, D

An SD-WAN rule is the correct, centralized mechanism in FortiOS to steer traffic based on application or service. By creating a rule that matches HTTP and setting WAN1 as the preferred member, you explicitly route that protocol out of WAN1 while optionally maintaining failover to WAN2 if WAN1 goes down. This approach leverages SD-WAN health-check and load-balancing logic, making it the most robust and policy-driven solution.

Why this answer

SD-WAN rules allow you to define application-based routing policies. By creating an SD-WAN rule that matches HTTP traffic and sets WAN1 as the preferred interface, the FortiGate will automatically steer HTTP sessions out through WAN1 while using the default routing table (which points to WAN2) for all other traffic. This leverages the SD-WAN feature's ability to perform per-application load balancing and failover without requiring policy-based routing.

Exam trap

The trap here is that candidates often confuse policy-based routing (Option D) with SD-WAN rules (Option A), not realizing that both are valid methods for application-based routing on FortiGate, and the question asks for TWO configurations needed, so both A and D are correct.

113
MCQeasy

Which of the following is a characteristic of policy-based NAT on a FortiGate?

A.NAT is configured directly in the firewall policy using the 'set nat' option
B.NAT is configured separately from firewall policies using Central NAT rules
C.NAT is applied to all traffic regardless of policy
D.NAT can only be used with IP pools
AnswerA

In policy-based NAT, the translation is an integral part of the firewall policy itself. The administrator enables NAT by setting the `nat` option to `enable` within that specific policy, optionally choosing an IP pool for source translation. This binds the translation rule directly to the policy's matching criteria, providing per-policy granularity, which is the defining characteristic of this approach.

Why this answer

Policy-based NAT on a FortiGate is configured directly within a firewall policy using the 'set nat' command. This allows NAT to be applied selectively based on the policy's matching criteria (source, destination, service, etc.), rather than being defined as a separate rule. This approach is the traditional method on FortiGate and is distinct from Central NAT, which decouples NAT rules from firewall policies.

Exam trap

The trap here is that candidates often confuse policy-based NAT with Central NAT (Option B), mistakenly thinking NAT must always be configured separately, but FortiGate supports both methods and the question specifically asks about policy-based NAT.

How to eliminate wrong answers

Option B is wrong because Central NAT rules are a separate feature where NAT is configured independently from firewall policies, which is the opposite of policy-based NAT. Option C is wrong because policy-based NAT is not applied to all traffic; it only applies to traffic that matches the specific firewall policy where NAT is enabled. Option D is wrong because policy-based NAT can use either IP pools or the interface IP address (via 'set nat' without an IP pool), so it is not limited to IP pools.

114
MCQeasy

An administrator is configuring a firewall policy on a FortiGate to allow internal users to access a web server on the internet. The administrator wants to log all traffic that matches this policy. Which logging option should be enabled on the policy to log traffic at the session start and end?

A.Log Allowed Traffic - All Sessions
B.Generate Logs when Session Starts
C.Log Allowed Traffic - Security Events
D.Capture Packets
AnswerA

This is correct because selecting 'All Sessions' under 'Log Allowed Traffic' causes the FortiGate to log every session that matches the policy, including the start and end of the session. This provides a complete record of allowed traffic. It is the appropriate setting when the administrator wants to log all traffic for auditing or troubleshooting purposes.

Why this answer

To log all allowed traffic including session start and end, the administrator should enable 'Log Allowed Traffic' and select 'All Sessions'. This setting ensures that every session matching the policy is logged, providing comprehensive visibility. Other options like logging only security events or only session start do not meet the requirement.

Capture Packets is for troubleshooting, not logging. This configuration is essential for auditing and monitoring network activity.

Exam trap

The trap here is confusing 'Log Allowed Traffic - All Sessions' with 'Generate Logs when Session Starts', which only logs the beginning of a session.

115
MCQeasy

Which statement best describes the 'implicit deny' policy on a FortiGate?

A.It can be moved to a different position in the policy list
B.It is automatically applied to all traffic that does not match any explicit policy
C.It is a configurable policy that denies all traffic
D.It logs all denied traffic by default
AnswerB

FortiGate evaluates traffic against explicit firewall policies in sequence; anything matching none of them is dropped by the implicit deny, which sits at the end of the policy list. It is not configured manually and applies automatically to all unmatched traffic.

Why this answer

The 'implicit deny' policy on a FortiGate is a built-in, last-resort rule that automatically denies any traffic not matching an explicit firewall policy. It is not visible in the policy list and cannot be moved, modified, or deleted; it is always applied as the final rule to ensure that only explicitly permitted traffic is allowed through the FortiGate.

Exam trap

The trap here is that candidates often confuse the implicit deny with a configurable policy, thinking it can be moved, logged, or modified, when in fact it is a fixed, non-configurable default rule that is always present and never logs traffic by default.

How to eliminate wrong answers

Option A is wrong because the implicit deny policy is not a movable entry in the policy list; it is a fixed, invisible rule that always resides at the bottom of the policy evaluation order. Option C is wrong because the implicit deny is not configurable — it is a hardcoded default behavior that cannot be edited or removed. Option D is wrong because the implicit deny does not log denied traffic by default; logging must be explicitly enabled on an explicit deny policy or via global logging settings.

116
MCQmedium

A network admin has configured a firewall policy allowing HTTPS traffic from the internal network to a DMZ web server. Users report that the web pages load slowly. The admin checks the policy and notices traffic shaping is not applied. What is the BEST action to ensure fair bandwidth distribution for HTTPS traffic?

A.Create a traffic shaping policy and apply it to the firewall policy
B.Increase the bandwidth of the internet link
C.Configure policy-based routing for HTTPS traffic
D.Enable QoS on the outgoing interface
AnswerA

In FortiGate, bandwidth control is enforced through traffic shaping policies that are directly referenced by a firewall policy. You can assign a shared or per-IP traffic shaper with guaranteed and maximum bandwidth values, plus a priority level, so matching HTTPS sessions get explicit bandwidth limits and fair distribution. This is the only option that applies per-policy rate limiting, allowing the administrator to cap and prioritize traffic without affecting other policies.

Why this answer

Traffic shaping is the correct mechanism to enforce fair bandwidth distribution for HTTPS traffic. By creating a traffic shaping policy and applying it to the firewall policy, the admin can allocate a specific bandwidth guarantee or limit for HTTPS sessions, preventing them from starving other traffic. Without shaping, HTTPS traffic can consume all available bandwidth, causing slow performance for other users.

Exam trap

The trap here is that candidates often confuse QoS (which prioritizes packets) with traffic shaping (which controls bandwidth allocation), leading them to select option D, but QoS alone does not enforce fair distribution of bandwidth across multiple sessions.

How to eliminate wrong answers

Option B is wrong because increasing the internet link bandwidth does not enforce fair distribution; it only adds more capacity, which can still be monopolized by aggressive HTTPS traffic. Option C is wrong because policy-based routing controls the path traffic takes, not bandwidth allocation; it does not shape or limit traffic. Option D is wrong because QoS on the outgoing interface is a lower-level mechanism that typically prioritizes packets based on DSCP or CoS values, but it does not provide the per-policy bandwidth control that traffic shaping offers in FortiGate.

117
MCQeasy

A FortiGate administrator configures a firewall policy to allow HTTP traffic from internal users to the internet. The policy uses source address 'internal_subnet', destination address 'all', and service 'HTTP'. After applying the policy, users report they cannot access websites. What is the most likely cause?

A.The source interface is misconfigured
B.The destination address object 'all' is incorrect
C.The policy order is incorrect and a deny policy above is blocking the traffic
D.The policy only allows HTTP (port 80), but users are likely accessing HTTPS (port 443)
AnswerD

The service object restricts the policy to TCP port 80 only, so browser sessions to port 443 match no permit rule and are dropped. Widening the service to HTTPS or ALL resolves the failure, since modern sites default to TLS.

Why this answer

The policy explicitly allows HTTP (TCP port 80), but modern web traffic predominantly uses HTTPS (TCP port 443). Since the service object does not include HTTPS, the firewall will drop HTTPS packets by default unless a separate policy or rule permits them. This is the most likely reason users cannot access websites, as most sites redirect HTTP to HTTPS or require HTTPS for secure connections.

Exam trap

The trap here is that candidates assume 'HTTP' covers all web traffic, but FortiGate treats HTTP and HTTPS as distinct services based on port numbers, and the implicit deny will block any unmatched traffic.

How to eliminate wrong answers

Option A is wrong because the source interface misconfiguration would typically cause a complete lack of connectivity for all traffic from that interface, not just web browsing, and the policy would not match at all. Option B is wrong because the destination address object 'all' is a valid FortiGate object that represents any destination IP address, and it is correct for allowing traffic to the internet. Option C is wrong because while policy order can affect traffic matching, the question states the policy was applied and there is no indication of a deny policy above; the most direct and common cause is the service mismatch.

118
Multi-Selectmedium

A FortiGate administrator needs to allow SMTP traffic (TCP port 25) from the internal network (10.0.0.0/8) to a mail server in the DMZ (172.16.0.10). The administrator wants to apply an antivirus profile and log all sessions. Which THREE configuration steps are required?

Select 3 answers
A.Create a schedule object and apply it to the policy
B.Create a firewall policy with source: 10.0.0.0/8, destination: 172.16.0.10, service: SMTP, action: ACCEPT
C.Create an antivirus profile and apply it to the policy
D.Configure NAT on the policy to translate source IPs
E.Enable logging on the firewall policy
AnswersB, C, E

A firewall policy with source 10.0.0.0/8, destination 172.16.0.10, service SMTP, and action ACCEPT is the fundamental permit rule needed to allow the SMTP traffic. FortiGate evaluates policies from top to bottom, and this tuple uniquely identifies the SMTP session directed to the mail server. Without such an explicit ACCEPT policy, the implicit deny rule would silently drop the traffic, so this is the correct baseline configuration.

Why this answer

A firewall policy must be created to allow SMTP traffic from the internal network (10.0.0.0/8) to the DMZ mail server (172.16.0.10) on TCP port 25. The policy must specify the source, destination, service (SMTP), and action (ACCEPT) to permit the traffic. Without this policy, the traffic would be blocked by default.

Exam trap

The trap here is that candidates often assume NAT is required for any traffic leaving a private network, but in FortiGate, NAT is only needed when the destination is on a different network segment that requires source address translation, such as the internet, not for internal-to-DMZ traffic.

119
MCQmedium

An administrator needs to apply traffic shaping to limit bandwidth for video streaming traffic on a firewall policy. Which configuration step is required?

A.Use an application control profile to restrict video streaming
B.Configure policy-based routing to shape traffic
C.Enable QoS on the interface and set the bandwidth limit
D.Create a traffic shaper and reference it in the firewall policy
AnswerD

Creating a traffic shaper defines the guaranteed and maximum bandwidth thresholds, then referencing it directly in the firewall policy applies those limits to matched video streaming traffic. This satisfies the requirement to shape bandwidth per policy, since FortiGate shapers only take effect once bound to the policy handling that traffic.

Why this answer

Traffic shaping in FortiGate is applied by creating a traffic shaper (either per-IP or shared) and then referencing that shaper in the firewall policy that matches the video streaming traffic. This allows the administrator to control bandwidth usage for specific traffic flows without affecting other traffic. Option D is correct because it directly describes this required configuration step.

Exam trap

The trap here is that candidates often confuse QoS interface settings (which limit all traffic on an interface) with traffic shapers (which limit specific traffic in a policy), leading them to select Option C instead of D.

How to eliminate wrong answers

Option A is wrong because an application control profile is used to identify and optionally block or allow applications, not to shape or limit bandwidth; it does not provide traffic shaping capabilities. Option B is wrong because policy-based routing (PBR) is used to route traffic based on source/destination or other attributes, not to shape or limit bandwidth; shaping is applied via traffic shapers in policies, not via routing decisions. Option C is wrong because enabling QoS on an interface sets a bandwidth limit for the entire interface, not for specific traffic types like video streaming; traffic shaping for specific applications requires a traffic shaper referenced in a firewall policy.

120
MCQeasy

An administrator wants to restrict access to a web server from only specific countries. The FortiGate is located at the network edge. Which address object type should be used in the source field of the firewall policy?

A.FQDN address object
B.Wildcard FQDN address object
C.Geography address object
D.Subnet address object
AnswerC

A geography address object in FortiOS is explicitly designed for geo-IP filtering. It references a country or region (e.g., China or Europe) by leveraging FortiGuard's geolocation database to map an IP address to a country. When used in a firewall policy's source or destination, it allows or denies traffic based on the client's geographic location, making it the correct and direct approach for restricting web server access by country.

Why this answer

A Geography address object allows the FortiGate to match traffic based on the source IP's country of origin, using the built-in GeoIP database. This is the only address object type that can restrict access by country without requiring manual IP range updates.

Exam trap

The trap here is that candidates may confuse Geography address objects with FQDN or Subnet objects, mistakenly thinking that a wildcard or domain-based object can filter by geographic location, when in fact only the Geography object leverages the FortiGate's GeoIP database for country-level matching.

How to eliminate wrong answers

Option A is wrong because an FQDN address object resolves to a specific IP address or set of IP addresses, not to a country or geographic region. Option B is wrong because a Wildcard FQDN address object matches domain names with wildcards (e.g., *.example.com) and is used for web filtering or DNS-based policies, not for geographic restrictions. Option D is wrong because a Subnet address object defines a specific IP range or network segment, which cannot dynamically represent all IPs from a particular country.

121
Multi-Selectmedium

A FortiGate administrator is implementing a policy to allow outbound traffic from the internal network to the internet. The requirements are: (1) all traffic from internal users must be source NATed to the external interface IP, (2) traffic from a specific server must use a different public IP, (3) HTTP traffic must be shaped to 10 Mbps. Which THREE configuration elements should the administrator create? (Choose three.)

Select 3 answers
A.A traffic shaper for HTTP traffic
B.A VIP for the server
C.A firewall policy with NAT enabled and the IP pool referenced
D.An IP Pool for the specific server's public IP
E.A policy-based routing rule for the server
AnswersA, C, D

Traffic shapers are used to control bandwidth usage and prioritize traffic. In this scenario, to allow HTTP traffic while ensuring it doesn't saturate the link, a traffic shaper can be applied to the firewall policy to guarantee or limit bandwidth for HTTP. It doesn't affect the destination or source IP translation; it's a QoS mechanism.

Why this answer

A traffic shaper is required to enforce bandwidth limits on HTTP traffic. In FortiGate, traffic shaping policies allow you to define per-policy bandwidth constraints, such as capping HTTP traffic to 10 Mbps, by applying a shaper to the firewall policy that matches HTTP traffic.

Exam trap

The trap here is confusing VIP (destination NAT) with IP pool (source NAT), leading candidates to incorrectly select VIP for source IP translation requirements.

122
MCQmedium

A FortiGate administrator wants to ensure that traffic from the 192.168.1.0/24 network to the internet is translated to a single public IP address using overload (PAT). Which NAT configuration should be used?

A.Policy-based NAT with a fixed port range
B.One-to-one NAT IP Pool
C.Virtual IP (VIP) with port forwarding
D.Central SNAT with a dynamic IP pool using overload
AnswerD

Central SNAT with a dynamic IP pool using overload is the correct approach because it implements many-to-one Source NAT: the FortiGate dynamically selects a public IP from the pool and rewrites each internal source IP to that public IP while also changing the source port to a unique value, enabling thousands of internal connections to share a single public address. Central NAT is the recommended method for outbound internet traffic because it cleanly separates NAT configuration from firewall policies and directly supports overload/PAT, matching the requirement for general internet egress.

Why this answer

Central SNAT with a dynamic IP pool using overload (PAT) is the correct method to translate all traffic from the 192.168.1.0/24 network to a single public IP address. The 'overload' option enables port address translation (PAT), allowing multiple internal hosts to share one public IP by using unique source port numbers, which is exactly what the administrator needs for internet-bound traffic.

Exam trap

The trap here is that candidates often confuse 'one-to-one NAT' (Option B) with PAT, thinking it can overload a single IP, but one-to-one NAT requires a dedicated public IP per internal host and does not perform port translation.

How to eliminate wrong answers

Option A is wrong because policy-based NAT with a fixed port range restricts the number of concurrent translations to the size of the port range, which would not allow all hosts in the /24 network to share a single IP efficiently and could exhaust ports quickly. Option B is wrong because one-to-one NAT IP Pool maps each internal IP to a unique public IP, requiring multiple public IPs and not supporting overload (PAT) to share a single IP. Option C is wrong because Virtual IP (VIP) with port forwarding is used for inbound destination NAT (port forwarding) to internal servers, not for outbound source NAT with overload to a single public IP.

123
MCQmedium

Given the exhibit, a user in the internal network tries to SSH to a public server (203.0.113.10). What will happen and why?

A.The SSH connection will succeed because policy 1 allows all services before policy 2 is evaluated.
B.The SSH connection will succeed because policy 2 is evaluated first.
C.The SSH connection will be blocked because policy 2 explicitly denies SSH.
D.The SSH connection will be blocked because policy 1 does not include SSH service specifically.
AnswerA

In FortiGate, firewall policies are evaluated sequentially from the top of the policy list downward. Because policy 1 matches all traffic from the internal interface to wan1 with service set to ALL, it includes SSH (TCP port 22). Since this allow policy is encountered first, it takes effect and the SSH session is permitted. Policy 2, even though it explicitly denies SSH, is never reached because the first match already decided the traffic's fate.

Why this answer

Policy 1 is an implicit allow-all rule that matches all traffic before policy 2 is evaluated. Since FortiGate processes policies in sequential order from top to bottom, the SSH connection to 203.0.113.10 matches policy 1 first, which permits all services, including SSH. Therefore, the connection succeeds without ever reaching policy 2.

Exam trap

The trap here is that candidates assume a deny rule later in the policy list will block traffic, forgetting that FortiGate uses first-match logic, so an earlier allow-all rule takes precedence.

How to eliminate wrong answers

Option B is wrong because policy 2 is not evaluated first; FortiGate evaluates policies in sequential order from top to bottom, so policy 1 is checked before policy 2. Option C is wrong because although policy 2 explicitly denies SSH, it is never reached due to the earlier match with policy 1. Option D is wrong because policy 1 does not need to include SSH specifically; it allows all services, which inherently includes SSH.

124
MCQmedium

A FortiGate administrator wants to ensure that traffic from the internal network to an external FTP server uses a specific source IP address (203.0.113.10). The internal network uses RFC 1918 addresses. Which NAT configuration should be used?

A.Policy-based NAT using an IP pool set to 'Fixed Port Range'
B.Virtual IP (VIP) mapping the internal server to 203.0.113.10
C.Central SNAT with dynamic IP pool
D.Policy-based NAT using an IP pool with type 'Overload' and the IP address 203.0.113.10
AnswerD

Policy-based NAT with an IP pool of type Overload performs source NAT by translating the source address of all matching sessions to the single IP defined in the pool. Since the pool contains only 203.0.113.10, every outbound session from the internal server will appear to originate from that exact IP using PAT (port address translation). This directly meets the requirement of ensuring all traffic from the server uses 203.0.113.10 as the source IP.

Why this answer

Policy-based NAT with an IP pool type 'Overload' (PAT) allows multiple internal hosts to share the single public IP 203.0.113.10 for outbound traffic. This meets the requirement to translate RFC 1918 source addresses to a specific source IP when accessing an external FTP server, while preserving port multiplexing.

Exam trap

The trap here is confusing VIP (inbound destination NAT) with source NAT (SNAT), leading candidates to select Option B, even though the requirement is for outbound traffic from internal clients to use a specific source IP.

How to eliminate wrong answers

Option A is wrong because 'Fixed Port Range' IP pools are used for static port allocation, typically for protocols that require predictable ports (e.g., SIP), not for general outbound source NAT with a single IP. Option B is wrong because a Virtual IP (VIP) is used for inbound destination NAT (port forwarding) to map an external IP to an internal server, not for outbound source NAT from internal clients. Option C is wrong because Central SNAT with a dynamic IP pool would select from a range of IPs, not guarantee the specific source IP 203.0.113.10.

125
MCQmedium

An administrator creates a firewall policy with a traffic shaper to limit bandwidth for guest wireless users. After applying the policy, users can still consume high bandwidth. The administrator confirms the policy is matching. What is the MOST likely reason the traffic shaper is not effective?

A.The traffic shaper's maximum bandwidth is set too high
B.The traffic shaper is applied to the wrong direction (egress vs ingress)
C.The traffic shaper is configured but not applied to the policy's 'Traffic Shaper' field
D.The traffic shaper is a per-IP shaper but the policy applies to a subnet
AnswerC

FortiGate traffic shapers are objects that must be explicitly referenced in a firewall policy; simply creating a shaper under Traffic Shaping does not cause any policy to use it. The firewall policy's 'Traffic Shaper' field and 'Per-IP Shaper' field both default to 'None', which means traffic matching the policy is forwarded with no bandwidth limitation. To enforce a shaping rule, the administrator must select the desired shaper in that drop-down field. When the shaper is left unassigned, the policy passes traffic at full interface speed, perfectly explaining the 'high bandwidth consumption' symptom.

Why this answer

In FortiGate, a traffic shaper must be explicitly selected in the 'Traffic Shaper' field of the firewall policy to be applied. Simply creating a shaper and configuring it is insufficient; the policy's shaper field links the shaper to the traffic. Without this link, the shaper is not enforced, even if the policy matches.

Exam trap

The trap here is that candidates assume creating a traffic shaper automatically applies it to all matching traffic, but FortiGate requires explicit assignment in the firewall policy's shaper field to enforce the limit.

How to eliminate wrong answers

Option A is wrong because setting the maximum bandwidth too high would still limit bandwidth, just at a higher threshold; it would not cause the shaper to be completely ineffective. Option B is wrong because traffic shapers in FortiGate are applied per policy and control both ingress and egress directions based on the shaper type (e.g., per-policy shaper applies to both directions); direction misconfiguration would not render the shaper entirely ineffective. Option D is wrong because a per-IP shaper applied to a subnet is valid and would limit each individual IP's bandwidth; it would not cause the shaper to be ineffective.

126
MCQmedium

An organization needs to restrict internet access for employees to business hours only (Monday to Friday, 8:00 to 18:00). Which object should the admin use in the firewall policy?

A.A schedule object with recurring time
B.A time-range object
C.An on-time schedule
D.A calendar object
AnswerA

A schedule object with recurring time is the standard FortiGate construct for defining repeating time periods. The 'recurring' type allows you to specify days of the week and a start/end time, and it remains active indefinitely. This precisely matches the requirement to restrict internet access for employees on a continuous, repeating basis. In a firewall policy, this object controls when the rule is enforced, enabling automated time-based access control.

Why this answer

A schedule object with recurring time is the correct choice because FortiGate firewall policies use schedule objects to define time-based access control. A recurring schedule allows you to specify days of the week and a time range (e.g., Monday to Friday, 8:00-18:00) that repeats weekly, which perfectly matches the requirement for business hours only.

Exam trap

The trap here is that candidates familiar with Cisco devices might confuse 'time-range object' (Cisco) with FortiGate's 'recurring schedule', leading them to select option B, which is not a valid FortiGate object.

How to eliminate wrong answers

Option B (a time-range object) is wrong because FortiGate does not use a 'time-range object'; that term is specific to Cisco IOS ACLs, not FortiGate. Option C (an on-time schedule) is wrong because FortiGate has no such object type; the correct term is 'recurring schedule' for repeating patterns. Option D (a calendar object) is wrong because FortiGate does not have a 'calendar object'; schedules are either one-time or recurring, and a calendar object is not a valid FortiGate object.

127
Multi-Selecteasy

A FortiGate admin is creating a firewall policy to allow outbound HTTP and HTTPS traffic from the internal network. The admin wants to ensure that traffic is inspected by security profiles (antivirus, web filter). Which THREE of the following must be configured on the firewall policy to achieve this?

Select 3 answers
A.Set the action to ACCEPT
B.Set the schedule to always
C.Apply an antivirus profile and a web filter profile to the policy
D.Configure the service to include HTTP and HTTPS
E.Enable NAT on the policy
AnswersA, C, D

The action parameter is the core permit or deny decision in a FortiOS firewall policy. Only when set to ACCEPT will the FortiGate allow the session to be established and forward traffic; DENY immediately drops packets and prevents any further processing. Security profiles can only operate on traffic that has passed this initial action check, so ACCEPT is the non-negotiable foundation for allowing outbound web traffic.

Why this answer

Setting the action to ACCEPT is mandatory for the firewall policy to allow traffic through. Without ACCEPT, the policy would deny traffic by default, preventing any inspection by security profiles. The ACCEPT action enables the FortiGate to process the traffic through the configured security profiles.

Exam trap

The trap here is that candidates often think NAT is required for outbound traffic inspection, but NAT is only for address translation and does not enable security profile processing; the key is the ACCEPT action and proper service/profile configuration.

128
MCQhard

A FortiGate admin configures an IP pool with type 'Fixed Port Range' to translate source IPs from 192.168.1.0/24 to 203.0.113.0/28 using port range 10000-20000. After applying the IP pool to a policy, some users cannot establish connections while others work. What is the MOST likely cause?

A.The internal subnet is using RFC 1918 addresses that cannot be NATed
B.The IP pool's port range is exhausted because the number of internal hosts exceeds the number of available port ranges
C.The IP pool is configured with overload enabled, causing conflicts
D.The firewall policy has NAT disabled
AnswerB

With a fixed-port-range IP pool, the FortiGate reserves a dedicated block of source ports per internal host on the pool's IP address. If you have more internal hosts than available port blocks (e.g., 5,000 hosts with only 4,000 blocks), later hosts receive no port allocation and their sessions are denied. This is a capacity limit caused by the deterministic, non-dynamic port-block allocation of the fixed-range mode.

Why this answer

Fixed Port Range NAT uses a one-to-one mapping of source IPs to unique port ranges. With a /28 pool (16 IPs) and port range 10000-20000 (10,001 ports), each internal host gets a dedicated port block. If more than 16 concurrent internal hosts attempt NAT, the pool is exhausted, causing connection failures for excess hosts.

This matches the symptom where some users work and others do not.

Exam trap

The trap here is confusing Fixed Port Range with Dynamic IP Pool (PAT), where overload allows many internal hosts to share a single external IP; candidates mistakenly think 'overload' is a setting in Fixed Port Range or that the port range itself is the bottleneck, rather than the number of external IPs.

How to eliminate wrong answers

Option A is wrong because RFC 1918 addresses are explicitly designed to be NATed to public IPs, and FortiGate supports NAT for private subnets. Option C is wrong because 'overload' (PAT) is not a configurable parameter for Fixed Port Range; this pool type inherently uses static port ranges without overload. Option D is wrong because the IP pool is applied to a policy, which implies NAT is enabled; if NAT were disabled, no translation would occur for any user.

129
MCQeasy

Which of the following describes the implicit deny action in FortiGate firewall policies?

A.A policy that is automatically created when the first policy is added
B.A policy that denies traffic based on the source IP
C.A policy that denies all traffic and can be moved to any position
D.A default policy that denies all traffic unless explicitly allowed
AnswerD

This is the correct description: the implicit deny is a default, unmodifiable behavior that denies all traffic unless a preceding explicit policy explicitly allows it. The firewall processes policies from top to bottom; when the packet does not match any configured allow or deny rule, it falls through to this built-in default, which silently discards the packet. This enforces a default-deny security posture, ensuring that only traffic explicitly permitted by an administrator can pass through the interface pair.

Why this answer

In FortiGate firewall policies, the implicit deny is a default, system-generated rule that denies all traffic not explicitly permitted by any configured policy. It is always present at the end of the policy list and cannot be moved, modified, or deleted. This ensures that any traffic not matching an explicit 'accept' policy is automatically dropped, enforcing a default-deny security posture.

Exam trap

The trap here is that candidates confuse the implicit deny with a user-created deny policy, thinking it can be moved or customized, when in fact it is a fixed, system-enforced rule that always resides at the end of the policy sequence.

How to eliminate wrong answers

Option A is wrong because the implicit deny is not created when the first policy is added; it exists by default even before any policies are configured. Option B is wrong because the implicit deny denies all traffic regardless of source IP, not just based on source IP. Option C is wrong because the implicit deny is always at the bottom of the policy list and cannot be moved to any position; it is fixed as the last policy.

130
Multi-Selecthard

A FortiGate admin is troubleshooting an issue where traffic from VLAN 10 to the internet is not being NATed even though a policy-based NAT rule is configured. The admin verifies that the firewall policy uses the correct IP Pool. Which THREE steps should the admin take to diagnose the problem? (Choose three.)

Select 3 answers
A.Reboot the FortiGate to clear any session table issues
B.Examine the IP Pool configuration for correct interface binding or port exhaustion
C.Verify that the firewall policy is being hit using 'diagnose firewall fwpolicy list' or logs
D.Check the session table using 'diagnose sys session list' to see if NAT is applied
E.Disable all other firewall policies to isolate the issue
AnswersB, C, D

The IP pool is where FortiGate defines the translated source IP(s) for NAT, so a misconfiguration here directly breaks translation. If the pool is bound to the wrong outgoing interface, traffic egressing the actual interface will not match the pool and will either be untranslated or dropped. Additionally, even with correct binding, an overloaded pool that runs out of available source ports (exhausted port range) will fail to allocate a translation for new sessions, producing a NAT failure that does not appear in policy checks.

Why this answer

Option B is correct because an IP Pool must be bound to the correct egress interface and must have available ports/addresses; if the pool is bound to the wrong interface or its ports are exhausted, NAT translation will not occur even though the policy references the pool. Option C is correct because the admin must confirm the policy is actually matching the traffic, which can be done with 'diagnose firewall fwpolicy list' or by reviewing policy logs; if the policy is not hit, NAT will never be applied. Option D is correct because 'diagnose sys session list' shows the live session table and whether NAT is applied, including the translated source IP and port, which directly reveals if NAT is failing.

Option A is not appropriate because rebooting is disruptive and does not diagnose the root cause of a NAT failure. Option E is not appropriate because disabling all other policies is a risky, non-diagnostic action that could cause an outage and does not isolate the NAT issue in a controlled way.

Exam trap

The trap here is that candidates often assume a firewall policy with NAT enabled will always work, overlooking that the IP Pool itself must be correctly bound to the egress interface and not exhausted, and that rebooting or disabling policies are not valid diagnostic steps.

131
MCQeasy

A FortiGate administrator wants to create a firewall policy that matches traffic based on the destination domain name (e.g., *.example.com). Which type of address object should be used?

A.FQDN object
B.Wildcard FQDN object
C.Subnet object
D.Geography object
AnswerB

A wildcard FQDN object is the correct object type because it supports pattern matching with an asterisk, for example `*.example.com`. This pattern matches both the apex domain and all of its subdomains in FortiGate policies, and the matching is performed against the hostname seen in the traffic, not against a single resolved IP address. It is ideal for allowing an entire domain family regardless of the underlying IP addresses.

Why this answer

A Wildcard FQDN object (option B) is the correct choice because it allows pattern matching with a leading asterisk (e.g., *.example.com) to match any subdomain of example.com. Standard FQDN objects require an exact, fully qualified domain name and do not support wildcard patterns, making them unsuitable for matching traffic based on a domain pattern like *.example.com.

Exam trap

The trap here is that candidates often confuse a standard FQDN object (which requires an exact match) with a Wildcard FQDN object (which supports pattern matching), leading them to incorrectly select option A when the question explicitly asks for a pattern like *.example.com.

How to eliminate wrong answers

Option A is wrong because a standard FQDN object requires an exact domain name (e.g., www.example.com) and does not support wildcard patterns, so it cannot match *.example.com. Option C is wrong because a Subnet object matches traffic based on IP address ranges or CIDR notation, not domain names. Option D is wrong because a Geography object matches traffic based on geographical location (country or region) using IP geolocation, not domain names.

132
MCQmedium

An administrator needs to configure a firewall policy to allow outbound traffic from the internal network to the internet. The internal network uses private IP addresses, and the FortiGate's WAN interface has a public IP. Which NAT configuration is appropriate to ensure return traffic is routed correctly?

A.Disable NAT and rely on the FortiGate's routing table to forward traffic.
B.Enable NAT and specify a custom IP pool with a private IP address.
C.Enable NAT in the firewall policy and use the outgoing interface address.
D.Create a VIP for the internal subnet and apply it as the source in the policy.
AnswerC

Enabling NAT in the policy and using the outgoing interface address translates the private source IPs to the public IP of the WAN interface. This is the standard configuration for outbound NAT (SNAT) and ensures that return traffic is sent back to the FortiGate, which then translates it back to the internal host. This meets the requirement.

Why this answer

For outbound internet access from a private network, source NAT must be enabled in the firewall policy, typically using the outgoing interface address. This translates private IPs to the public IP of the WAN interface, allowing return traffic to reach the FortiGate and be forwarded back to the internal hosts. Other options either use incorrect NAT types or fail to translate to a routable address.

Exam trap

The trap here is confusing source NAT with destination NAT (VIP) or using a private IP pool for translation.

133
MCQmedium

An admin wants to block all traffic from a specific geographic region. Which address object type should be used in the firewall policy source?

A.FQDN
B.Subnet
C.IP range
D.Geography
AnswerD

Geography address objects are predefined FortiGuard-maintained collections of IP ranges mapped to countries or regions. Referencing a Geography object in the firewall policy source matches traffic by geolocation, blocking all traffic originating from the specified region without manually enumerating IP addresses.

Why this answer

FortiGate firewalls include a built-in Geography address object type that allows policies to match traffic based on the source or destination IP address's registered country or region. This object uses GeoIP databases to classify IP addresses, enabling administrators to block or allow traffic from entire geographic areas without needing to manually list individual subnets or ranges.

Exam trap

The trap here is that candidates may confuse Geography with IP range or subnet, thinking they can manually compile a list of all IPs for a region, but FortiGate's Geography object automates this via the GeoIP database and is the correct, scalable approach for geographic blocking.

How to eliminate wrong answers

Option A is wrong because FQDN (Fully Qualified Domain Name) objects resolve to IP addresses via DNS and are used for policies based on domain names, not geographic location. Option B is wrong because a Subnet object defines a contiguous block of IP addresses using a network prefix (e.g., 192.168.1.0/24) and cannot represent an entire geographic region. Option C is wrong because an IP range object specifies a start and end IP address (e.g., 10.0.0.1-10.0.0.255) and is intended for arbitrary address ranges, not for geographic classification.

134
MCQhard

A FortiGate with multiple VDOMs has a policy that allows traffic from VDOM A to VDOM B. The admin notices that traffic from VDOM A to a specific server in VDOM B is being dropped. The session log shows 'deny by forward policy check'. What is the MOST likely cause?

A.The inter-VDOM link is down
B.NAT is required for inter-VDOM traffic
C.The source VDOM has exceeded its session limit
D.The policy in VDOM B to allow traffic from VDOM A is missing or misconfigured
AnswerD

In a multi-VDOM FortiGate, traffic leaving VDOM A and entering VDOM B must match a forward policy in VDOM B that permits the traffic from the inter-VDOM link interface to the destination interface. If that policy is missing, misconfigured (e.g., wrong source/destination addresses, wrong service, or disabled action), the packet is implicitly denied by the firewall's default-deny behavior. The error message would reflect a forward policy check failure, making this the correct explanation for the traffic being blocked.

Why this answer

The session log message 'deny by forward policy check' indicates that the traffic was explicitly denied by a firewall policy rule, not by a routing or resource issue. In a multi-VDOM setup, traffic from VDOM A to VDOM B must be permitted by a policy in VDOM B (the destination VDOM) that allows traffic from the inter-VDOM link or from VDOM A. If that policy is missing or misconfigured, the FortiGate will drop the traffic and log this exact denial.

Exam trap

The trap here is that candidates often assume inter-VDOM traffic is implicitly allowed or that the source VDOM's policy controls the flow, but in reality each VDOM has its own independent policy set and the destination VDOM must have an explicit permit policy for the traffic to be forwarded.

How to eliminate wrong answers

Option A is wrong because an inter-VDOM link being down would cause a routing or connectivity failure, not a 'deny by forward policy check' log entry; the session would show 'no route' or 'link down' instead. Option B is wrong because NAT is not required for inter-VDOM traffic; inter-VDOM communication can be routed without NAT unless explicitly configured for address translation. Option C is wrong because a session limit exceeded would generate a 'session limit reached' or 'resource exhausted' log, not a policy-based deny message.

135
MCQmedium

A company has a web server in the DMZ that needs to be accessible from the internet on port 443 (HTTPS). The administrator configures a Virtual IP (VIP) mapping the public IP 203.0.113.10 to the private IP 10.0.1.10 port 443. Which firewall policy is required to allow inbound traffic?

A.A policy from WAN to DMZ with source any, destination IP of the server (10.0.1.10), and action ACCEPT
B.A policy from WAN to DMZ with source any, destination VIP, and action ACCEPT
C.No firewall policy is needed; the VIP automatically allows traffic
D.A policy from DMZ to WAN with source VIP, destination any, and action ACCEPT
AnswerB

This is the correct way to publish a server. The VIP object defines the public-to-private IP mapping, and the policy uses that VIP as the destination to explicitly allow inbound traffic. After the policy is matched, FortiOS performs destination NAT, replacing the VIP IP with the server's private IP and forwarding the packet to the DMZ. This ensures that all traffic is inspected and controlled by the firewall.

Why this answer

When a Virtual IP (VIP) is configured in FortiGate, the firewall policy must reference the VIP object as the destination, not the actual private IP. The VIP translates the public IP (203.0.113.10) to the private IP (10.0.1.10), and the policy from WAN to DMZ with destination VIP ensures that inbound traffic is matched and permitted before NAT translation occurs. Without this policy, the VIP alone does not allow traffic; it only defines the translation rule.

Exam trap

The trap here is that candidates often assume a VIP automatically permits traffic or that the policy should use the private IP, but FortiGate requires an explicit firewall policy referencing the VIP object to allow inbound traffic through the NAT mapping.

How to eliminate wrong answers

Option A is wrong because the policy must use the VIP object as the destination, not the actual private IP (10.0.1.10); referencing the private IP bypasses the NAT translation and will not match the incoming traffic destined to the public IP. Option C is wrong because a VIP does not automatically allow traffic; it only defines the NAT mapping, and a corresponding firewall policy with action ACCEPT is mandatory to permit the traffic. Option D is wrong because the required policy must be from WAN to DMZ (inbound direction), not from DMZ to WAN; the DMZ-to-WAN policy would control outbound responses, not the initial inbound connection.

136
MCQmedium

A FortiGate administrator needs to create a firewall policy that allows traffic from the internal network (10.0.0.0/8) to a public web server (203.0.113.10) on port 443. The policy must also perform source NAT using the FortiGate's external IP (198.51.100.1). Which NAT configuration should be applied?

A.Create an IP pool with the external IP and reference it in the firewall policy
B.Enable NAT on the firewall policy without specifying an IP pool
C.Create a VIP for the web server and reference it in the firewall policy
D.Configure Central SNAT and a matching rule
AnswerB

When you enable NAT on a firewall policy and leave the IP pool field blank, FortiOS performs source NAT using the primary IP address of the egress interface—here, 198.51.100.1. This is the simplest and most common method for enabling internet access from a private network, as it requires no separate NAT objects or additional configuration. The NAT action is directly part of the policy, exactly matching the scenario's request to apply NAT to the policy itself.

Why this answer

When a firewall policy uses source NAT (SNAT) to translate internal source IPs to the FortiGate's own egress interface IP, simply enabling NAT on the policy without specifying an IP pool is sufficient. This is the default behavior: the FortiGate automatically performs source NAT using the IP address of the outgoing interface (in this case, 198.51.100.1). No additional IP pool or central NAT rule is required for this standard outbound NAT scenario.

Exam trap

The trap here is that candidates often confuse source NAT with destination NAT and incorrectly select a VIP (option C), or they overcomplicate the scenario by assuming an IP pool is always required for NAT, when in fact the default interface NAT is sufficient when the goal is to use the FortiGate's own external IP.

How to eliminate wrong answers

Option A is wrong because creating an IP pool is necessary only when you need to translate to a specific IP address that is not the egress interface IP, or when you need to use a range of IPs (e.g., for load balancing or hiding many internal hosts behind a smaller set of public IPs). Here, the requirement is to use the FortiGate's own external IP, which is the default behavior when NAT is enabled without a pool. Option C is wrong because a Virtual IP (VIP) is used for destination NAT (DNAT), i.e., translating an incoming public IP to an internal private IP, not for source NAT.

The question asks for source NAT, so a VIP is irrelevant. Option D is wrong because Central SNAT is an alternative method for configuring source NAT, but it is not required; the question does not specify a need for central NAT management, and the standard policy-based NAT (enabling NAT on the policy) is the simplest and correct approach for this scenario.

137
MCQeasy

Which of the following best describes the policy lookup order on a FortiGate firewall?

A.Policies are evaluated in the order they appear in the policy list, from top to bottom
B.Policies are evaluated based on the number of hits, least-hit first
C.Policies are evaluated randomly to balance load
D.The policy with the highest priority number is evaluated first
AnswerA

FortiGate firewall policies are stored in a sequential list, and the session engine traverses that list in the exact order the administrator has arranged them, from the topmost entry (index 0) downward. The first policy whose source, destination, service, and other match conditions all align with the session's attributes is immediately applied, and no further policies are consulted for that session. This deterministic top-down approach is why moving a policy to a new position can dramatically change traffic handling, even if the policy's own match fields remain identical.

Why this answer

FortiGate firewalls evaluate firewall policies sequentially from the top of the policy list downward. The first policy that matches the source, destination, service, and other attributes of a packet is applied, and no further policies are checked. This top-down evaluation ensures deterministic traffic handling and is fundamental to FortiGate's stateful inspection engine.

Exam trap

The trap here is that candidates often confuse FortiGate's top-down sequential policy lookup with Cisco ASA's concept of 'first match wins' but may incorrectly assume that hit counts or priority numbers influence the evaluation order, which is not the case on FortiGate.

How to eliminate wrong answers

Option B is wrong because FortiGate does not use hit count to determine policy order; policies are evaluated by their position in the list, not by usage statistics. Option C is wrong because policy evaluation is deterministic and sequential, not random, as random evaluation would break security consistency and is not supported. Option D is wrong because FortiGate uses policy ID order (lower IDs are evaluated first by default) or manual ordering, not a priority number; higher priority numbers do not cause earlier evaluation.

138
MCQmedium

A FortiGate admin runs 'diagnose sys session filter src 10.0.0.10' and gets no output. What does this indicate?

A.The session table is full
B.The source IP 10.0.0.10 is not currently active in any session table
C.The firewall policy is blocking traffic from 10.0.0.10
D.The diagnose command syntax is incorrect
AnswerB

The kernel session table tracks active, stateful connections, and when you apply a source-IP filter, it displays only sessions whose source address matches the filter. If no output is returned, it means the source 10.0.0.10 currently has no session entry — the host is idle, its session expired or was torn down, or it never established one. This is a straightforward observation of the session table state, not a sign of a performance or configuration issue.

Why this answer

The 'diagnose sys session filter' command in FortiGate is used to filter and display active session entries in the session table. When the command 'diagnose sys session filter src 10.0.0.10' returns no output, it means that no session in the session table matches the source IP address 10.0.0.10, indicating that this IP is not currently involved in any active session. This does not imply the session table is full, a policy block, or a syntax error.

Exam trap

The trap here is that candidates may assume no output means a syntax error or a full session table, but FortiGate clearly indicates syntax errors with an error message, and a full table still shows existing sessions; the correct interpretation is that the source IP has no active sessions.

How to eliminate wrong answers

Option A is wrong because a full session table would still show sessions that match the filter, or the command would return an error or warning about table capacity, not simply no output. Option C is wrong because a firewall policy blocking traffic would prevent sessions from being created, but the command only checks the session table; if no session exists, it returns no output regardless of the policy reason. Option D is wrong because the syntax 'diagnose sys session filter src 10.0.0.10' is correct; if the syntax were incorrect, FortiGate would return a syntax error message, not a blank output.

139
MCQhard

A FortiGate has a central SNAT policy that translates internal users to a single IP pool address. The admin wants specific traffic (e.g., from a particular subnet) to use a different IP pool. What is the correct approach?

A.Create a new central SNAT policy with the specific subnet as source and place it above the existing policy
B.Create a policy-based NAT rule with the specific subnet and place it above the central SNAT policy
C.Use VIP to translate the source address
D.Modify the existing central SNAT policy to use a dynamic IP pool
AnswerA

Central SNAT policies are evaluated in strict top-down order, and the first policy whose source, destination, and service criteria match the traffic is applied. By creating a new policy with a more specific source subnet (e.g., 10.1.1.0/24) and placing it above the existing broader policy, you guarantee that traffic from that subnet is translated according to the new policy, while all other traffic falls through to the original policy below. This is the standard way to implement selective source translation when central NAT is enabled.

Why this answer

Central SNAT policies are evaluated in sequential order, and the first matching policy is applied. By creating a new policy with the specific subnet as the source and placing it above the existing policy, the FortiGate will match the more specific traffic first and use the different IP pool, while all other traffic continues to match the original policy.

Exam trap

The trap here is that candidates often confuse central SNAT with policy-based NAT or VIP, mistakenly thinking that VIPs can be used for source NAT or that PBNAT rules can be inserted into the central NAT table, when in fact central SNAT policies are a distinct feature with their own ordered list.

How to eliminate wrong answers

Option B is wrong because policy-based NAT (PBNAT) is a legacy feature that operates within firewall policies, not as a separate NAT policy table; placing a PBNAT rule above a central SNAT policy is not a valid configuration as they are different mechanisms. Option C is wrong because a Virtual IP (VIP) is used for destination NAT (DNAT), translating incoming traffic's destination IP, not for source NAT (SNAT) of outbound traffic. Option D is wrong because modifying the existing central SNAT policy to use a dynamic IP pool would apply that pool to all traffic matching the policy, not just the specific subnet, failing to achieve the requirement of using a different IP pool for that subnet.

140
MCQmedium

A company has a FortiGate with multiple VDOMs. An admin creates a firewall policy in the root VDOM to allow traffic from a subnet to the internet. The traffic is not matching the policy. What is the most likely cause?

A.The traffic is in a different VDOM than the policy
B.The internet-facing interface is not part of any VDOM
C.The subnet object is defined in the wrong address group
D.The policy is placed at the bottom of the list
AnswerA

Each VDOM on a FortiGate operates as an independent virtual firewall with its own routing table, policy set, and interface associations. A firewall policy configured in the root VDOM only examines traffic whose ingress and egress interfaces belong to that same VDOM. If the traffic flows through interfaces assigned to VDOM2, the root policy is never evaluated, so the traffic is instead subject to VDOM2's own policy list, and the mismatch explains why the policy has no effect.

Why this answer

In a multi-VDOM FortiGate, each VDOM operates as an independent virtual firewall with its own routing table, policies, and interfaces. A firewall policy created in the root VDOM only applies to traffic that enters and exits interfaces assigned to that root VDOM. If the traffic originates from or is destined to an interface belonging to a different VDOM, it will never match the root VDOM policy, causing the traffic to be dropped or handled by the correct VDOM's policies.

Exam trap

The trap here is that candidates assume a policy in the root VDOM applies to all traffic by default, not realizing that VDOMs create strict administrative boundaries where policies are only effective within their own VDOM.

How to eliminate wrong answers

Option B is wrong because an internet-facing interface must be assigned to a VDOM to function; unassigned interfaces are not operational and cannot pass traffic. Option C is wrong because even if the subnet object is in the wrong address group, the policy would still match if the source IP falls within the defined subnet range; the issue is VDOM isolation, not address group membership. Option D is wrong because policy order only matters within the same VDOM; a policy at the bottom of the list in the root VDOM would still match traffic that belongs to the root VDOM, but it cannot match traffic from a different VDOM regardless of its position.

141
MCQeasy

Which of the following statements about firewall policy ordering in FortiGate is correct?

A.Policies are evaluated from bottom to top
B.The most specific policy always takes precedence regardless of order
C.Policies are evaluated from top to bottom, and the first match is applied
D.The implicit permit rule at the end allows all traffic not explicitly denied
AnswerC

This is the core behavior of FortiGate's firewall policy engine: policies are read from top to bottom, and the first policy whose all matching criteria (source, destination, service, etc.) match the traffic is applied. Once a match is found, the remaining policies are not evaluated. You control this order by arranging policies, and it is typically visualized as a numbered list in both GUI and CLI.

Why this answer

FortiGate firewall policies are evaluated sequentially from top to bottom in the policy list. The first policy that matches the source, destination, service, and other criteria is applied, and no further policies are evaluated. This is the fundamental 'first-match' behavior that governs traffic processing in FortiGate.

Exam trap

The trap here is that candidates often confuse FortiGate's top-down first-match logic with other firewall platforms that use bottom-up evaluation or automatic specificity-based precedence, leading them to select option A or B.

How to eliminate wrong answers

Option A is wrong because FortiGate evaluates policies from top to bottom, not bottom to top; bottom-to-top evaluation is a common misconception from other firewall platforms. Option B is wrong because FortiGate does not automatically prioritize the most specific policy; order in the policy list determines precedence, and a more specific policy placed lower will never be reached if a less specific policy above matches first. Option D is wrong because the implicit deny rule at the end of the policy list silently drops all traffic that does not match any explicit policy; there is no implicit permit rule in FortiGate.

142
Multi-Selecthard

An admin needs to configure a FortiGate to allow multiple internal servers to be accessible from the internet using the same public IP but different ports. For example, internal server A (192.168.1.10:80) should be reachable via 203.0.113.10:8080, and internal server B (192.168.1.20:443) via 203.0.113.10:8443. Which TWO configuration steps are required?

Select 2 answers
A.Create two separate VIPs, one for each server, and add them to a VIP group
B.Disable NAT on the policy to preserve the source IP
C.Configure a firewall policy with destination set to the VIP group and action set to allow
D.Configure Central SNAT to translate the source IP
E.Create a single VIP with port forwarding that maps multiple ports
AnswersA, C

A VIP group aggregates multiple Virtual IP (VIP) objects into a single destination address object. Each VIP in the group has its own external-to-internal IP/port mapping, so when the group is used as a policy destination, the FortiGate checks the inbound packet against each VIP member, performs the matching DNAT, and forwards to the correct internal server. This design is the only way to expose two different internal servers through distinct public IPs/ports under one logical policy.

Why this answer

Each internal server requires a unique Virtual IP (VIP) to map a specific external port to a specific internal IP and port. Adding these VIPs to a VIP group allows a single firewall policy to reference all of them, enabling the FortiGate to differentiate traffic based on the destination port and forward it to the correct internal server.

Exam trap

The trap here is that candidates often think a single VIP with multiple port mappings can handle different internal servers, but FortiGate VIPs are one-to-one mappings; a VIP group is required to aggregate multiple VIPs under one policy.

143
MCQeasy

A FortiGate admin wants to ensure that traffic destined to a specific web server is inspected by an IPS profile. Which configuration is necessary?

A.Enable IPS on the firewall policy directly
B.Set the policy's action to 'IPS'
C.Create a security profile group containing the IPS profile and apply it to the policy
D.Configure a VIP for the web server
AnswerC

The correct approach is to create a security profile group that contains the IPS sensor and then apply that group to the firewall policy governing traffic to the web server. This groups the IPS sensor with other inspection profiles, enabling layered UTM inspection on accepted traffic. When the policy action is ACCEPT and the profile group is attached, all matching sessions are inspected by the IPS engine against its configured signatures and rules.

Why this answer

In FortiGate, IPS inspection is applied via a security profile group that includes the IPS profile, which is then attached to a firewall policy. The firewall policy itself does not have a direct 'enable IPS' toggle; instead, IPS profiles are part of the security profiles that must be explicitly assigned to the policy to inspect traffic.

Exam trap

The trap here is that candidates may think IPS can be enabled directly on the policy or that a special policy action exists for IPS, but FortiGate requires IPS to be applied as a security profile, not as a policy attribute.

How to eliminate wrong answers

Option A is wrong because FortiGate does not allow enabling IPS directly on the firewall policy; IPS is a security profile that must be applied through a security profile group or individually. Option B is wrong because setting the policy's action to 'IPS' is not a valid configuration; the policy action is either 'ACCEPT' or 'DENY', and IPS inspection is configured separately via security profiles. Option D is wrong because configuring a Virtual IP (VIP) is used for destination NAT and port forwarding, not for applying IPS inspection to traffic.

144
MCQhard

During a security audit, the administrator runs the command 'diagnose firewall policy list' and sees the following output: policy id=1: allow from port1 to port2, src=10.0.0.0/8, dst=any, action=accept policy id=2: deny from port1 to port2, src=10.0.0.0/8, dst=172.16.0.0/12, action=deny policy id=3: allow from port1 to port2, src=any, dst=any, action=accept A host with IP 10.0.1.5 sends traffic to 172.16.0.1. Which policy will match?

A.Policy 3
B.Policy 1
C.Implicit deny
D.Policy 2
AnswerB

Policy 1 is correct because FortiGate uses a first-match model: it scans the policy list top-down and applies the first policy whose source, destination, and services match the packet. The source address in the traffic is within the 10.0.0.0/8 address range and the destination is any, so policy 1 matches all conditions for this session. Even though policy 2 may be more specific, it is placed after policy 1 and is therefore shadowed; the firewall never evaluates it for this traffic. Therefore policy 1's action (permit or deny) is what the audit should record.

Why this answer

Policy 1 matches first because FortiGate evaluates policies sequentially by ID. The source 10.0.1.5 is within 10.0.0.0/8 and the destination is any, so policy 1 matches and accepts the traffic. Although policy 2 would also match (172.16.0.1 is within 172.16.0.0/12), it is not evaluated because the first matching policy is applied.

Exam trap

The trap here is that candidates assume a deny rule with a more specific destination will override a broader allow rule, forgetting that FortiGate uses first-match logic based on policy ID order, not longest-prefix matching or specificity.

How to eliminate wrong answers

Option A is wrong because policy 3 is an 'allow any/any' catch-all, but it is evaluated after policy 1 and policy 2; since policy 1 matches first, policy 3 is never reached. Option C is wrong because the implicit deny only applies if no explicit policy matches; here policy 1 matches, so the traffic is accepted before any implicit deny is considered. Option D is wrong because policy 2's destination is 172.16.0.0/12, which includes 172.16.0.1, but policy 1 has a lower ID and matches first, so policy 2 is not evaluated for this traffic.

145
MCQmedium

An admin creates a firewall policy allowing HTTP traffic from internal users to the internet. Users complain that they cannot access HTTPS websites. The admin checks and sees that the policy only has HTTP service. What is the BEST course of action to allow HTTPS while maintaining security?

A.Create a new policy above the existing one with HTTPS service
B.Add the HTTPS service to the existing policy
C.Use a security policy that automatically adds HTTPS
D.Change the HTTP service to ALL services
AnswerB

Adding the HTTPS service object to the existing policy is the correct and most efficient approach. The policy already matches the desired source (internal users) and destination (internet) with a permit action for HTTP; extending the service list to include HTTPS (port 443/tcp) requires no change to the other match criteria or security profiles. This preserves least privilege by allowing only the specific web protocols intended, while avoiding policy duplication and administrative overhead. FortiGate security policies allow multiple service objects, so HTTP and HTTPS can coexist cleanly in the same rule.

Why this answer

Adding the HTTPS service (TCP/443) to the existing policy allows HTTPS traffic without creating a separate rule, which could introduce complexity or misordering issues. This approach maintains security by explicitly permitting only the required service rather than opening all traffic. FortiGate policies evaluate services as part of the match criteria, so modifying the existing policy is the most efficient and secure method.

Exam trap

The trap here is that candidates often think creating a new policy above the existing one is necessary for ordering, but FortiGate allows multiple services in a single policy, making modification the best practice for simplicity and security.

How to eliminate wrong answers

Option A is wrong because creating a new policy above the existing one could cause HTTPS traffic to match the new rule, but it introduces unnecessary policy bloat and potential misordering; however, the main issue is that it is less efficient than simply modifying the existing policy. Option C is wrong because FortiGate does not have a 'security policy that automatically adds HTTPS' — policies must be explicitly configured with the desired services. Option D is wrong because changing the service to ALL would permit all traffic (including unwanted protocols), violating the principle of least privilege and reducing security.

146
Multi-Selectmedium

An administrator wants to configure traffic shaping to limit bandwidth for YouTube video streaming. Which THREE objects or settings must be configured on the FortiGate to apply traffic shaping?

Select 3 answers
A.Traffic shaper (e.g., shared or per-IP shaper)
B.Application control profile to identify YouTube traffic
C.A DNS filter to block YouTube
D.A firewall policy that applies the traffic shaper and the application control profile
E.A static route for YouTube's IP range
AnswersA, B, D

A traffic shaper (shared or per-IP) is the concrete bandwidth-limiting mechanism. It defines maximum and/or guaranteed bandwidth rates in kilobits per second, and a per-IP shaper applies those limits independently to each client IP address, whereas a shared shaper aggregates all matching traffic under one bucket. This directly throttles throughput for the matched traffic, which is exactly what the administrator wants to accomplish for YouTube.

Why this answer

A traffic shaper (shared or per-IP) defines the bandwidth limits (e.g., maximum rate, guaranteed rate) that will be enforced on the traffic. This shaper must be created first to control YouTube streaming bandwidth.

Exam trap

The trap here is that candidates may think DNS filtering or static routes are needed for shaping, but FortiGate relies on application control for traffic identification and a firewall policy to bind the shaper, not on DNS or routing.

147
MCQhard

A FortiGate is configured with multiple policies. The first policy allows traffic from 10.0.0.0/8 to any destination. The second policy denies traffic from 10.0.1.0/24 to any destination. What happens when a packet from 10.0.1.5 to 8.8.8.8 arrives?

A.The packet is denied by implicit deny
B.The packet is allowed by the first policy
C.The packet matches both policies and is allowed
D.The packet is denied by the second policy
AnswerB

The first policy's source address range of 10.0.0.0/8 encompasses the packet's source IP 10.0.1.5, and if the other matching criteria (destination, service, incoming/outgoing interface) also align, FortiGate applies that policy's allow action. Policy evaluation is sequential and stops at the first match, so the allow decision is executed immediately. This makes the first policy the definitive rule that governs this traffic, regardless of what later policies define.

Why this answer

FortiGate firewall policies are evaluated in sequential order from top to bottom. The first policy matches source 10.0.0.0/8, which includes 10.0.1.5, and allows the traffic to any destination. Since the packet matches this policy first, it is accepted and the second policy is never evaluated.

Therefore, the packet is allowed by the first policy.

Exam trap

The trap here is that candidates often assume FortiGate uses a longest-prefix match or that a more specific deny policy will override a broader allow policy, but FortiGate strictly follows first-match order, not prefix length.

How to eliminate wrong answers

Option A is wrong because the packet matches an explicit allow policy (the first policy) before any implicit deny rule can apply; implicit deny only triggers when no explicit policy matches. Option C is wrong because FortiGate uses first-match logic, not a longest-prefix or combined-match approach; once a packet matches the first policy, subsequent policies are not checked. Option D is wrong because the second policy is never reached; the packet is evaluated against the first policy, which matches and allows it, so the deny policy is ignored.

148
MCQmedium

A FortiGate has multiple WAN interfaces (port1, port2) connected to different ISPs. The administrator wants traffic from the internal network to use port1 for general internet access but use port2 for traffic to a specific cloud service (203.0.113.0/24). Which feature should be used to achieve this?

A.Create a VIP for the cloud service
B.Configure static routes with different distances
C.Use SD-WAN rules to load balance
D.Use policy-based routing (PBR) to route traffic based on destination
AnswerD

Policy-based routing (PBR) allows a FortiGate to match traffic using source and destination IP, port, protocol, or even application, and explicitly assign the outgoing interface and source address. This lets you send traffic destined to a specific cloud service through port1 or port2 regardless of the default routing table lookup. PBR is the correct way to implement a static, destination-based WAN selection for specific services.

Why this answer

Policy-based routing (PBR) allows you to override the default routing table based on criteria such as source/destination IP, protocol, or port. In this scenario, PBR can match traffic destined to 203.0.113.0/24 and force it out through port2, while all other internet traffic follows the default route via port1. This provides granular control without affecting the general routing behavior.

Exam trap

The trap here is that candidates often confuse SD-WAN load balancing with policy-based routing, assuming that SD-WAN rules can enforce a strict 'always use this interface for this destination' policy, when in fact SD-WAN is primarily for dynamic load balancing and failover, not for static, deterministic path selection based solely on destination.

How to eliminate wrong answers

Option A is wrong because a Virtual IP (VIP) is used for destination NAT (port forwarding) to map a public IP to an internal server, not to control outbound path selection. Option B is wrong because static routes with different distances influence the routing table based on administrative distance, but they cannot selectively route traffic based on destination subnet when both interfaces have a default route; they would simply prefer one default route over the other for all traffic. Option C is wrong because SD-WAN rules load-balance or failover traffic across multiple links based on performance metrics or volume, but they do not provide the deterministic, policy-based path selection required to send specific traffic to a specific interface while using another for general internet access.

149
Multi-Selectmedium

A FortiGate admin needs to block all traffic from the 'Guest' VLAN (192.168.100.0/24) to the internal network (10.0.0.0/8) except for DNS traffic (UDP 53) to the internal DNS server at 10.0.0.10. Which TWO firewall policy configuration elements are required to achieve this? (Choose two.)

Select 2 answers
A.An address group for the internal DNS server
B.A firewall policy with source 'Guest' VLAN, destination 'Internal network', service 'ALL', action 'deny'
C.A firewall policy with source 'Guest' VLAN, destination 'Internal DNS server', service 'DNS', action 'accept'
D.A traffic shaper to limit DNS traffic
E.A schedule object to apply the policies only during business hours
AnswersB, C

This is the key deny-all policy: setting source to the Guest VLAN, destination to the Internal network, service to ALL, and action to DENY creates a catch-all that blocks every non-explicitly-allowed guest-to-internal flow. In FortiOS, policies are evaluated top-down on a first-match basis, so this deny must be placed after the DNS accept policy (or a higher priority allow) if DNS is to remain permitted. Without this deny rule, any implicit or later allow policies could still let guest traffic reach internal resources.

Why this answer

A deny policy with source 'Guest' VLAN (192.168.100.0/24), destination 'Internal network' (10.0.0.0/8), and service 'ALL' will block all traffic from the Guest VLAN to the internal network. Option C is correct because an explicit accept policy for DNS (UDP 53) to the internal DNS server (10.0.0.10) must be placed before the deny policy, as FortiGate firewall policies are evaluated in order from top to bottom, and the first matching policy determines the action.

Exam trap

The trap here is that candidates often think an address group (Option A) is necessary for the DNS server, but a single address object works just as well, and the real key is the policy ordering between the explicit accept and the explicit deny.

150
Multi-Selectmedium

A network admin needs to configure a FortiGate to allow remote VPN users (IPsec VPN) to access a web server in the DMZ. The VPN users are assigned IPs from 10.10.10.0/24. The web server is at 192.168.2.10:80. Which TWO objects must be created to define the traffic for the firewall policy? (Choose two.)

Select 2 answers
A.A service object for HTTP (TCP/80)
B.An address object for the web server 192.168.2.10
C.An address object for the VPN user subnet 10.10.10.0/24
D.A user group object for VPN authentication
E.A schedule object for business hours
AnswersB, C

The web server address object is mandatory because it defines the destination of the traffic in the firewall policy. FortiGate requires both source and destination address objects in every IPv4 policy, and this object uniquely identifies 192.168.2.10 as the server. Without it, the policy cannot match traffic to the web server, so the rule cannot be correctly created.

Why this answer

The firewall policy must specify the destination address of the traffic, which is the web server at 192.168.2.10. Without an address object for this server, the policy cannot match the destination IP of the VPN users' HTTP requests.

Exam trap

The trap here is that candidates often think a service object must be created for HTTP, but FortiGate includes predefined services for common protocols like HTTP, making custom creation unnecessary unless the port is non-standard.

← PreviousPage 2 of 3 · 193 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Firewall Policies and NAT questions.