NSE4 Firewall Policies and NAT Practice Question
Which of the following is a characteristic of policy-based NAT on a FortiGate?
⚠ Common exam trap
Many candidates confuse policy-based NAT with Central NAT (Option B), mistakenly thinking NAT must always be configured separately, but FortiGate supports both methods and the question specifically asks about policy-based NAT.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NAT is configured directly in the firewall policy using the 'set nat' option
Policy-based NAT on a FortiGate is configured directly within a firewall policy using the 'set nat' command. This allows NAT to be applied selectively based on the policy's matching criteria (source, destination, service, etc.), rather than being defined as a separate rule. This approach is the traditional method on FortiGate and is distinct from Central NAT, which decouples NAT rules from firewall policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NAT is configured directly in the firewall policy using the 'set nat' option
Why this is correct
In policy-based NAT, the translation is an integral part of the firewall policy itself. The administrator enables NAT by setting the `nat` option to `enable` within that specific policy, optionally choosing an IP pool for source translation. This binds the translation rule directly to the policy's matching criteria, providing per-policy granularity, which is the defining characteristic of this approach.
- ✗
NAT is configured separately from firewall policies using Central NAT rules
Why it's wrong here
Central NAT is a separate feature that uses dedicated central SNAT and DNAT rule tables, independent of firewall policies. In this model, a firewall policy still controls access, but the actual translation is matched by central NAT rules based on source/destination addresses and services, not by a `set nat` toggle inside the policy. This is the alternative configuration style, not the policy-based one described in the question.
- ✗
NAT is applied to all traffic regardless of policy
Why it's wrong here
NAT never applies globally to all traffic simply because a firewall is in the path; it is triggered only when traffic matches a firewall policy that has NAT explicitly enabled. With policy-based NAT, a policy without the `nat` setting enabled passes traffic untranslated. Thus, saying NAT applies to all traffic regardless of policy contradicts the core per-policy essence of policy-based NAT.
- ✗
NAT can only be used with IP pools
Why it's wrong here
Policy-based NAT does not mandate the use of an IP pool; without a pool, the FortiGate will use the outgoing interface's IP address for source NAT (also known as overload or PAT). An IP pool is simply an optional resource that can be selected within the policy when you need to translate to a specific range or multiple public addresses. Therefore, the claim that IP pools are the only option is incorrect.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.