Why External Users Get Timeout When VIP Policy Destination Is Wrong
An administrator configures a VIP for port forwarding: public IP 203.0.113.10 port 8080 to internal server 10.0.1.10 port 80. External users can connect to http://203.0.113.10:8080 but receive a timeout. The firewall policy allows traffic from any to the VIP on destination port 8080. The internal server is reachable from internal hosts. What is the most likely problem?
⚠ Common exam trap
The trap here is that candidates mistakenly think the policy should match the internal server's port (80) because the VIP translates to that port, but FortiOS policy evaluation occurs before NAT, so the policy must match the original destination port (8080).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy destination service is set to HTTP (port 80) instead of port 8080
The firewall policy must match the destination port of the incoming traffic. External users connect to port 8080 on the VIP, but if the policy's destination service is set to HTTP (port 80), the policy will not match traffic destined for port 8080. Even though the VIP translates the destination to port 80 on the internal server, the firewall policy evaluation occurs before NAT translation, so the policy must match the original destination port (8080).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The internal server is not running a web server
Why it's wrong here
The internal server not running a web server is not the cause because the server is reachable from internal hosts, confirming that it is operational and listening on the intended port. FortiGate does not perform health checks on VIP destinations; it simply forwards traffic based on the policy and VIP mapping. If the server were down or not serving web traffic, internal users would also be unable to access it, so this would be a separate network-level issue unrelated to the FortiGate policy configuration.
- ✗
The VIP is not associated with the policy
Why it's wrong here
The VIP is definitely associated with the policy because the policy explicitly uses the VIP as its destination address. In FortiGate, a VIP is a virtual object that must be referenced as the destination in the IPv4 policy to be applied; if it were not, the policy would not match the traffic at all. Since the administrator did set the VIP as the destination, the problem must lie in another parameter, such as the service definition, not in association.
- ✓
The policy destination service is set to HTTP (port 80) instead of port 8080
Why this is correct
The policy's destination service is incorrectly set to HTTP (port 80) instead of the pre-NAT destination port 8080. FortiGate evaluates firewall policies against the packet's original destination port before any NAT translation occurs, so the policy must match the port the client connects to (i.e., the external port on the VIP, 8080). Using service HTTP (port 80) will cause the implicit deny rule to drop the packets because the session's destination port does not match the policy's service. The correct fix is to change the service to the pre-NAT port (e.g., a custom TCP/8080 service) or adjust the VIP to listen on port 80.
- ✗
The source NAT is not configured
Why it's wrong here
Source NAT is not required for inbound destination NAT because DNAT only changes the destination IP and port of the packet, while the source IP remains the external client's address. If the internal server has a route back to the client through the FortiGate (default gateway), reply packets will be processed by the firewall's stateful inspection, which automatically performs the reverse translation. The absence of source NAT does not prevent the initial connection from being established, so it cannot be the reason for the port-forwarding failure.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator configures a Virtual IP (VIP) to map the public IP 203.0.113.10 port 8080 to the internal server 192.168.1.100 port 80. External users report they cannot connect. The firewall policy allows inbound traffic to the VIP. What is the MOST likely missing configuration?
medium- ✓ A.The destination in the firewall policy is set to the public IP directly instead of the VIP object
- B.The VIP is configured with port forwarding disabled
- C.The server's default gateway is not set to the FortiGate
- D.The source NAT is not configured
Why A: When a Virtual IP (VIP) is configured, the firewall policy must reference the VIP object as the destination, not the public IP address directly. If the policy uses the public IP (203.0.113.10) as the destination, the FortiGate will not perform the destination NAT translation to the internal server (192.168.1.100). The VIP object contains the mapping logic, so the policy must point to that object for the translation to occur.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.