Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which of the following is a characteristic of policy-based NAT on a FortiGate?

⚠ Common exam trap

Many candidates confuse policy-based NAT with Central NAT (Option B), mistakenly thinking NAT must always be configured separately, but FortiGate supports both methods and the question specifically asks about policy-based NAT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NAT is configured directly in the firewall policy using the 'set nat' option

Policy-based NAT on a FortiGate is configured directly within a firewall policy using the 'set nat' command. This allows NAT to be applied selectively based on the policy's matching criteria (source, destination, service, etc.), rather than being defined as a separate rule. This approach is the traditional method on FortiGate and is distinct from Central NAT, which decouples NAT rules from firewall policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NAT is configured directly in the firewall policy using the 'set nat' option

    Why this is correct

    In policy-based NAT, the translation is an integral part of the firewall policy itself. The administrator enables NAT by setting the `nat` option to `enable` within that specific policy, optionally choosing an IP pool for source translation. This binds the translation rule directly to the policy's matching criteria, providing per-policy granularity, which is the defining characteristic of this approach.

  • ✗

    NAT is configured separately from firewall policies using Central NAT rules

    Why it's wrong here

    Central NAT is a separate feature that uses dedicated central SNAT and DNAT rule tables, independent of firewall policies. In this model, a firewall policy still controls access, but the actual translation is matched by central NAT rules based on source/destination addresses and services, not by a `set nat` toggle inside the policy. This is the alternative configuration style, not the policy-based one described in the question.

  • ✗

    NAT is applied to all traffic regardless of policy

    Why it's wrong here

    NAT never applies globally to all traffic simply because a firewall is in the path; it is triggered only when traffic matches a firewall policy that has NAT explicitly enabled. With policy-based NAT, a policy without the `nat` setting enabled passes traffic untranslated. Thus, saying NAT applies to all traffic regardless of policy contradicts the core per-policy essence of policy-based NAT.

  • ✗

    NAT can only be used with IP pools

    Why it's wrong here

    Policy-based NAT does not mandate the use of an IP pool; without a pool, the FortiGate will use the outgoing interface's IP address for source NAT (also known as overload or PAT). An IP pool is simply an optional resource that can be selected within the policy when you need to translate to a specific range or multiple public addresses. Therefore, the claim that IP pools are the only option is incorrect.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.