A FortiGate administrator wants to ensure that traffic from the internal network to the internet is translated to a single public IP address. Which NAT method should be used?
Overload NAT, also known as Port Address Translation (PAT), is the correct method for this scenario. It translates the source IP address of all internal hosts to one public IP while dynamically assigning a unique source port for each connection, preserving the host identity through the port mapping. This provides scalable, concurrent internet access for many internal users using a single public address.
Why this answer
Overload NAT (also known as Port Address Translation or PAT) is the correct method because it allows multiple internal hosts to share a single public IP address by mapping each session to a unique source port. This is exactly what the administrator needs: translating all internal-to-internet traffic to one public IP.
Exam trap
The trap here is that candidates often confuse 'Central SNAT' (a FortiGate configuration method) with a specific NAT type, or think 'one-to-one NAT' is suitable for sharing a single IP, when it actually requires a dedicated public IP per internal host.
How to eliminate wrong answers
Option A is wrong because Central SNAT is a policy-based NAT method in FortiGate that can use overload or other modes, but it is not a specific NAT method itself; it is a configuration approach. Option B is wrong because one-to-one NAT maps a single private IP to a single public IP, which would require multiple public IPs for multiple internal hosts, not a single public IP. Option C is wrong because fixed port range NAT allocates a fixed range of ports per internal host, which still requires multiple public IPs or port ranges and does not achieve the goal of using a single public IP for all traffic.