Courseiva

NSE4 · topic practice

Firewall Policies and NAT practice questions

Firewall Policies and NAT covers how FortiGate evaluates traffic: policy matching, NAT modes, VIPs, IP pools, and authentication. Questions use CLI scenarios, diagnose debug flow output, and policy configuration choices to test whether you can predict how traffic is permitted, translated, and logged.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Firewall Policies and NAT

What the exam tests

What to know about Firewall Policies and NAT

Be able to read a FortiGate policy and predict permit, deny, and NAT behavior, including VIP destination translation and SNAT pool selection. The most important thing is matching the correct source, destination, and service objects, then verifying with diagnose debug flow.

Order and matching of firewall policies, including implicit deny and policy lookup

Configuring SNAT with IP pools and central NAT versus policy NAT

VIP and virtual server configuration, including port forwarding and destination translation

FSSO and authentication conditions required for identity-based firewall policies

Why learners struggle

Why Firewall Policies and NAT questions are commonly missed

NAT questions are missed when learners confuse the four address types (inside local, inside global, outside local, outside global) or misapply the interface direction. A translation rule can look correct but still fail if the ACL, interface, or direction is wrong.

  • ·Inside local vs inside global — inside local is the private source, inside global is the translated public address
  • ·PAT overloads — many sources share one public IP using unique port numbers
  • ·Interface direction — ip nat inside and ip nat outside must be on the correct interfaces
  • ·Static NAT vs dynamic NAT vs PAT — each serves a different use case
  • ·The NAT ACL identifies traffic to translate, not traffic to permit or deny
  • ·A missing translation can look like a routing problem if the interfaces are misconfigured

Watch out for

Common Firewall Policies and NAT exam traps

  • ▸Using the VIP external IP as destination in the policy instead of the VIP object, or confusing pre-translation and post-translation addresses in debug flow output
  • ▸Forgetting that FSSO policies require the user to be authenticated and the FSSO collector agent or agentless polling to be reachable and working
  • ▸Assuming NAT is applied automatically; SNAT requires an IP pool or outgoing interface address, and policy order determines whether NAT is applied

Practice set

Firewall Policies and NAT questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full NAT/PAT explanation →

A network administrator configures a firewall policy to allow HTTP traffic from the internal network (10.0.0.0/8) to a web server (172.16.1.10). Users on the 10.0.0.0/8 network cannot access the web server, but other internal users can. The administrator checks the policy list and sees the policy is enabled and in the correct position. What is the most likely cause?

Question 2mediummultiple choice
Read the full NAT/PAT explanation →

Refer to the exhibit. A FortiGate has this policy configured. Traffic from 10.0.1.0/24 to 192.168.1.10 on HTTP is being logged as allowed. However, users report that they cannot access the web server. What is the most likely issue?

Exhibit

config firewall policy
    edit 1
        set name "Allow-HTTP"
        set srcintf "internal"
        set dstintf "dmz"
        set srcaddr "10.0.1.0/24"
        set dstaddr "192.168.1.10"
        set action accept
        set schedule "always"
        set service "HTTP"
        set logtraffic all
    next
end
Question 3hardmultiple choice
Read the full NAT/PAT explanation →

Refer to the exhibit. An administrator runs 'diagnose firewall auth list' and sees two authenticated users. The firewall policy requires authentication for HTTP traffic from 10.0.0.0/24 to 192.168.1.10. User 'jsmith' has been idle for 20 minutes, but the authentication session is still active. The idle timeout is set to 30 minutes. What will happen after 30 minutes of inactivity?

Exhibit

FGT # diagnose firewall auth list
1: authid=1 type=ldap user=jsmith src=10.0.0.5 dst=192.168.1.10 proto=6 port=80 duration=1200 timeout=3600
2: authid=2 type=ldap user=ajones src=10.0.0.6 dst=192.168.1.10 proto=6 port=80 duration=600 timeout=3600
Question 4hardmultiple choice
Study the full SD-WAN breakdown →

A company has a FortiGate 100F with two ISPs (ISP1 and ISP2) for load balancing. They use SD-WAN to direct traffic. The firewall has a policy that allows HTTP and HTTPS traffic from internal users (10.0.0.0/8) to the internet. The policy uses FSSO authentication with an Active Directory domain controller. Recently, users on the 10.0.1.0/24 subnet report that they are prompted for authentication repeatedly, even though they are domain-joined and logged in. Users on other subnets do not have this issue. The administrator checks the FSSO configuration and sees that the collector agent is running and the FortiGate is receiving login events. The FortiGate's policy is configured with source address 10.0.0.0/8 and FSSO group 'Domain Users'. The administrator also notices that the FortiGate's SD-WAN rules are configured to use ISP1 for traffic from 10.0.0.0/8 except for traffic from 10.0.1.0/24, which uses ISP2. The FortiGate's FSSO collector agent is configured to listen on the IP address 192.168.1.1, which is the IP of the interface connected to ISP1. What is the most likely cause of the authentication issue?

Question 5mediumdrag order
Read the full VPN explanation →

Drag and drop the steps to configure SSL VPN on FortiGate into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each FortiGate logging destination to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stored on the FortiGate's internal memory or disk

Centralized log collector and analyzer

Standard protocol to send logs to external servers

Cloud-based log storage and management

Used for monitoring device status and performance

Question 7mediummultiple choice
Read the full NAT/PAT explanation →

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

Question 8easymultiple choice
Read the full NAT/PAT explanation →

Which of the following is a valid address object type in FortiGate that can be used to match traffic based on the domain name of the destination?

Question 9mediummulti select
Read the full NAT/PAT explanation →

A FortiGate admin is troubleshooting a policy that should allow VoIP traffic. The admin suspects that the SIP ALG is interfering. Which TWO actions should the admin take to verify or resolve the issue?

Question 10mediummultiple choice
Read the full NAT/PAT explanation →

A network administrator configures a firewall policy allowing HTTP traffic from the internal network (10.0.0.0/8) to the internet. After applying the policy, users report they can browse the web, but the FortiGate logs show that all sessions are using the 'implicit deny' policy ID 0. What is the most likely cause?

Question 11mediummultiple choice
Read the full NAT/PAT explanation →

An administrator wants to ensure that traffic from the engineering department (subnet 192.168.10.0/24) to the internet uses a specific public IP address for source NAT. Additionally, traffic from the marketing department (192.168.20.0/24) should use a different public IP. Which method should be used?

Question 12mediummultiple choice
Read the full NAT/PAT explanation →

A FortiGate has two firewall policies: Policy 1 (from port1 to port2, source all, destination 10.0.1.0/24, schedule always, action accept) and Policy 2 (from port1 to port2, source all, destination all, schedule 'Business Hours', action accept). A user attempts to connect from port1 to 10.0.1.5 at 8 PM on a Saturday. The traffic is denied. What is the most likely reason?

Question 13mediummultiple choice
Read the full NAT/PAT explanation →

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

Question 14easymultiple choice
Read the full DNS explanation →

Which type of address object allows a FortiGate to perform DNS resolution to match traffic based on a domain name?

Question 15mediummultiple choice
Read the full NAT/PAT explanation →

A FortiGate admin configures a VIP to map 203.0.113.10:80 to 10.0.1.10:8080. However, when external users connect to http://203.0.113.10, they receive a connection timeout. The firewall policy allows the traffic. What is the most likely cause?

Question 16hardmultiple choice
Read the full NAT/PAT explanation →

An admin configures a one-to-one IP Pool to map 10.0.1.0/28 to 203.0.113.16/28. A host with IP 10.0.1.5 initiates a connection to the internet. Which source IP will be used for the translated packet?

Question 17easymultiple choice
Read the full NAT/PAT explanation →

Which of the following is the default action of a FortiGate firewall policy if no policy matches the traffic?

Question 18mediummulti select
Read the full NAT/PAT explanation →

A FortiGate admin wants to ensure that traffic from the internal network (192.168.1.0/24) to the internet uses a specific public IP (203.0.113.10) for source NAT, and that the same public IP is also used for inbound connections to an internal web server (10.0.1.10) on port 443. Which TWO configurations are required? (Choose two.)

Question 19hardmultiple choice
Read the full NAT/PAT explanation →

An administrator configures a VIP for inbound HTTP traffic to an internal server (192.168.1.10:80). External users can reach the server via the VIP, but internal users on the same subnet as the server cannot access the server using its public IP. What is the most likely cause?

Question 20hardmultiple choice
Read the full NAT/PAT explanation →

An administrator needs to allow traffic from a guest network (192.168.100.0/24) to the internet only during business hours (Mon-Fri, 08:00-18:00). The administrator creates a schedule object and applies it to the firewall policy. However, guests can still access the internet outside of the schedule. What is the most likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Firewall Policies and NAT sessions

Start a Firewall Policies and NAT only practice session

Every question in these sessions is drawn from the Firewall Policies and NAT domain — nothing else.

Related practice questions

Related NSE4 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the NSE4 exam test about Firewall Policies and NAT?
Be able to read a FortiGate policy and predict permit, deny, and NAT behavior, including VIP destination translation and SNAT pool selection. The most important thing is matching the correct source, destination, and service objects, then verifying with diagnose debug flow.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Firewall Policies and NAT questions in a focused session?
Yes — the session launcher on this page draws every question from the Firewall Policies and NAT domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other NSE4 topics?
Use the topic links above to move to related areas, or go back to the NSE4 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the NSE4 exam covers. They are not copied from any real exam or dump site.