Courseiva

Why Policy-Based Routing May Be Overridden by Firewall Policy

What is the purpose of policy-based routing (PBR) in FortiGate?

⚠ Common exam trap

Many candidates confuse PBR with SD-WAN or load balancing, but PBR is strictly about overriding routing decisions based on packet attributes, not about distributing traffic across multiple links for bandwidth or redundancy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To route traffic based on source address, destination, or other attributes instead of the routing table

Policy-based routing (PBR) in FortiGate allows you to override the default routing table lookup by forwarding traffic based on criteria such as source IP address, destination IP address, protocol, or even application. This is configured under the 'policy route' feature and is evaluated before the routing table, enabling granular control over traffic paths that static or dynamic routes cannot provide.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To load balance traffic across multiple WAN links

    Why it's wrong here

    Load balancing across multiple WAN links typically relies on SD-WAN intelligent steering or ECMP, which distribute flows based on metrics, weights, or link health. PBR (policy-based routing) can be used to assert a fixed next-hop for specific traffic, but it does not by itself perform load balancing or failover decisions. In FortiOS, SD-WAN rules and ECMP are the mechanisms designed for that purpose.

  • ✗

    To filter traffic based on application signatures

    Why it's wrong here

    Filtering by application signature is accomplished by the FortiGate application control profile, which inspects traffic at Layer 7 and identifies applications such as Facebook or BitTorrent. PBR instead operates at a lower level by matching Layer 3/4 attributes like source address, destination address, and service port. While a policy route can steer a whole subnet's traffic, it cannot classify individual applications the way an application control profile can.

  • ✓

    To route traffic based on source address, destination, or other attributes instead of the routing table

    Why this is correct

    Policy-based routing (PBR) allows a FortiGate to choose the next hop for a packet based on policy criteria such as source address, destination address, or incoming interface, rather than performing a normal longest-prefix routing table lookup. When a policy route matches, the FortiGate follows its configured action (e.g., send to a specific gateway or tunnel) and skips the destination-based routing decision for that packet. This is an essential tool when traffic must be forced down a specific path independent of what the routing table would select.

  • ✗

    To authenticate users before allowing traffic

    Why it's wrong here

    User authentication on FortiGate is handled by firewall authentication, which can use local users or remote servers like LDAP, or by captive portal for guest access. These features verify identity and then associate the authenticated user with firewall and identity-based policies. PBR does not perform authentication; it may only check user/group as an optional match criterion after a user has already authenticated, making it a routing tool, not an authentication mechanism.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate with multiple WAN interfaces uses policy-based routing (PBR) to route traffic from a specific subnet out of a particular interface. The admin also has a firewall policy allowing that subnet to the internet. However, the traffic is not being routed as expected. What could be the issue?

hard
  • A.The firewall policy is placed above the PBR rule
  • B.The PBR rule does not have a matching protocol or service defined
  • ✓ C.The PBR rule uses an incorrect source or destination address
  • D.The FortiGate is in transparent mode

Why C: Policy-based routing (PBR) is evaluated before firewall policies. If the PBR rule specifies an incorrect source or destination address, traffic from the intended subnet will not match the PBR rule and will fall through to the default routing table, potentially exiting via a different interface. The firewall policy alone cannot override the routing decision; the PBR rule must correctly identify the traffic to steer it to the desired egress interface.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.