Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

A FortiGate is configured with a VIP (virtual IP) for an internal web server. Users report that the web server is unreachable from the internet, but it works from the internal network. The administrator runs 'diagnose sniffer packet any "host 203.0.113.10 and port 80" 4' and sees incoming packets on the wan1 interface but no outgoing packets on the internal interface. What is the MOST likely cause?

⚠ Common exam trap

The trap here is assuming that configuring a VIP automatically allows traffic, when in fact a firewall policy is still needed to permit the DNATed traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall policy allowing traffic from wan1 to the internal server is missing or misconfigured.

When a VIP is used, the FortiGate performs destination NAT, but a firewall policy from the external interface to the internal interface (or the VIP's mapped interface) is still required to allow the translated traffic. The sniffer output indicates that packets arrive but are not forwarded, which is characteristic of a missing or incorrect policy. The VIP itself does not bypass policy checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VIP is configured with port forwarding disabled.

    Why it's wrong here

    If port forwarding were disabled, the VIP would map all ports to the internal server, but the sniffer would still show outgoing packets if a policy allowed the traffic. The absence of outgoing packets points to a policy issue, not port forwarding settings.

  • ✗

    The VIP is not configured with the correct external IP address.

    Why it's wrong here

    If the VIP external IP were incorrect, the sniffer would not show incoming packets destined to the VIP's external IP. Since packets are seen arriving on wan1 with the correct destination, the VIP external IP is likely correct. The issue lies elsewhere.

  • ✗

    The internal web server is down or not responding.

    Why it's wrong here

    If the internal server were down, the FortiGate would still forward the packets to the internal interface (unless it has a route issue) and the sniffer would show outgoing packets. The absence of outgoing packets suggests the FortiGate is not forwarding, not that the server is unresponsive.

  • ✓

    The firewall policy allowing traffic from wan1 to the internal server is missing or misconfigured.

    Why this is correct

    The sniffer shows incoming packets on wan1 but no outgoing packets on the internal interface, indicating the FortiGate is dropping the traffic after ingress. This typically happens when no firewall policy matches the traffic from wan1 to the internal network, or the policy is misconfigured (e.g., wrong service, action deny). The VIP itself only performs DNAT; a policy is still required to permit the translated traffic.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.