NSE4 Firewall Policies and NAT Practice Question
Exhibit
config firewall policy
edit 0
set name "Deny-All"
set srcintf "any"
set dstintf "any"
set srcaddr "all"
set dstaddr "all"
set action deny
set schedule "always"
set service "ALL"
set logtraffic all
next
edit 1
set name "Allow-HTTP"
set srcintf "internal"
set dstintf "wan1"
set srcaddr "10.0.0.0/8"
set dstaddr "all"
set action accept
set schedule "always"
set service "HTTP"
set logtraffic all
next
endRefer to the exhibit. An administrator configures the policies as shown. Traffic from 10.0.0.0/8 to the internet on HTTP is denied. What is the most likely reason?
⚠ Common exam trap
Many exam-takers assume policies are evaluated based on a 'most specific match' logic rather than the actual sequential order, leading them to overlook the policy placement as the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Deny-All policy is placed above the Allow-HTTP policy
In FortiGate firewall policies, the first matching policy is applied to traffic. The Deny-All policy is placed above the Allow-HTTP policy, so traffic from 10.0.0.0/8 to the internet on HTTP matches the Deny-All policy first and is denied before reaching the Allow-HTTP policy. This is a classic policy ordering issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Allow-HTTP policy uses service HTTP but the traffic uses HTTPS
Why it's wrong here
The Allow-HTTP policy specifying service HTTP is actually correct for this scenario because the traffic in question is HTTP, not HTTPS. FortiOS service objects define both protocol and port, so HTTP (TCP 80) matches the HTTP traffic. If the traffic were HTTPS, this would cause a mismatch, but that contradicts the given premise. Therefore, the service configuration is not the issue.
- ✓
The Deny-All policy is placed above the Allow-HTTP policy
Why this is correct
In FortiOS, policy evaluation is top-down and first-match; the first policy whose source/destination/service matches the traffic is applied. The Deny-All policy has a lower sequence number (e.g., policy ID 0) and appears above the Allow-HTTP policy, so it matches all traffic and denies the HTTP session before the allow policy is ever evaluated. Specificity does not override order, so the deny-all wins.
- ✗
The Allow-HTTP policy has the wrong source interface
Why it's wrong here
The source interface is the FortiGate ingress interface for the traffic, and the exhibit shows the HTTP traffic arrives on the correct internal interface that is configured as the source of the Allow-HTTP policy. If the source interface were wrong, the policy would not even be considered for matching, but here the traffic does match the source requirement. The actual problem is that an earlier policy denies the traffic before this match can occur.
- ✗
The Allow-HTTP policy is disabled
Why it's wrong here
A disabled policy in FortiOS appears greyed out and is skipped entirely during policy matching. The exhibit shows the Allow-HTTP policy is enabled with no disabled icon, so it is active and capable of matching traffic. Even if it were disabled, simply enabling it would not resolve the issue because the Deny-All policy still sits above it and would continue to drop the traffic. Hence, the disabled state is not the cause.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.