Why Policy-Based Routing May Be Overridden by Firewall Policy
What is the purpose of policy-based routing (PBR) in FortiGate?
⚠ Common exam trap
Many candidates confuse PBR with SD-WAN or load balancing, but PBR is strictly about overriding routing decisions based on packet attributes, not about distributing traffic across multiple links for bandwidth or redundancy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To route traffic based on source address, destination, or other attributes instead of the routing table
Policy-based routing (PBR) in FortiGate allows you to override the default routing table lookup by forwarding traffic based on criteria such as source IP address, destination IP address, protocol, or even application. This is configured under the 'policy route' feature and is evaluated before the routing table, enabling granular control over traffic paths that static or dynamic routes cannot provide.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To load balance traffic across multiple WAN links
Why it's wrong here
Load balancing across multiple WAN links typically relies on SD-WAN intelligent steering or ECMP, which distribute flows based on metrics, weights, or link health. PBR (policy-based routing) can be used to assert a fixed next-hop for specific traffic, but it does not by itself perform load balancing or failover decisions. In FortiOS, SD-WAN rules and ECMP are the mechanisms designed for that purpose.
- ✗
To filter traffic based on application signatures
Why it's wrong here
Filtering by application signature is accomplished by the FortiGate application control profile, which inspects traffic at Layer 7 and identifies applications such as Facebook or BitTorrent. PBR instead operates at a lower level by matching Layer 3/4 attributes like source address, destination address, and service port. While a policy route can steer a whole subnet's traffic, it cannot classify individual applications the way an application control profile can.
- ✓
To route traffic based on source address, destination, or other attributes instead of the routing table
Why this is correct
Policy-based routing (PBR) allows a FortiGate to choose the next hop for a packet based on policy criteria such as source address, destination address, or incoming interface, rather than performing a normal longest-prefix routing table lookup. When a policy route matches, the FortiGate follows its configured action (e.g., send to a specific gateway or tunnel) and skips the destination-based routing decision for that packet. This is an essential tool when traffic must be forced down a specific path independent of what the routing table would select.
- ✗
To authenticate users before allowing traffic
Why it's wrong here
User authentication on FortiGate is handled by firewall authentication, which can use local users or remote servers like LDAP, or by captive portal for guest access. These features verify identity and then associate the authenticated user with firewall and identity-based policies. PBR does not perform authentication; it may only check user/group as an optional match criterion after a user has already authenticated, making it a routing tool, not an authentication mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate with multiple WAN interfaces uses policy-based routing (PBR) to route traffic from a specific subnet out of a particular interface. The admin also has a firewall policy allowing that subnet to the internet. However, the traffic is not being routed as expected. What could be the issue?
hard- A.The firewall policy is placed above the PBR rule
- B.The PBR rule does not have a matching protocol or service defined
- ✓ C.The PBR rule uses an incorrect source or destination address
- D.The FortiGate is in transparent mode
Why C: Policy-based routing (PBR) is evaluated before firewall policies. If the PBR rule specifies an incorrect source or destination address, traffic from the intended subnet will not match the PBR rule and will fall through to the default routing table, potentially exiting via a different interface. The firewall policy alone cannot override the routing decision; the PBR rule must correctly identify the traffic to steer it to the desired egress interface.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.