NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate is configured with a VIP (virtual IP) to publish an internal web server to the internet. External users report that they cannot access the web server, but internal users can access it using its private IP. The administrator runs 'diagnose debug flow' and sees that traffic from external users is being dropped with the message 'iprope_in_check() check failed, drop'. What is the most likely cause?
⚠ Common exam trap
The trap here is interpreting the iprope_in_check failure as an RPF issue, but it often means no matching policy or a deny policy was hit first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall policy allowing access to the VIP is missing or placed after a deny policy.
The debug message 'iprope_in_check() check failed, drop' indicates that the traffic was dropped during the ingress policy check. This typically happens when no firewall policy matches the traffic or when a deny policy is matched before an allow policy. In this scenario, external users cannot access the VIP, but internal users can, suggesting the VIP itself is working. The most likely cause is that the firewall policy allowing external access to the VIP is missing, disabled, or incorrectly ordered. The administrator should verify the policy configuration and order.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall policy allowing access to the VIP does not have NAT enabled.
Why it's wrong here
If NAT were not enabled, the internal server would see the external source IP, and return traffic might not route correctly. However, the debug message 'iprope_in_check() check failed' typically indicates an RPF check failure, not a NAT issue. NAT issues would manifest differently, such as asymmetric routing or connection failures. Therefore, this is not the most likely cause.
- ✓
The firewall policy allowing access to the VIP is missing or placed after a deny policy.
Why this is correct
The debug message 'iprope_in_check() check failed, drop' indicates that the traffic was dropped during the ingress policy check, often because no matching policy was found or a deny policy was matched. If the policy allowing access to the VIP is missing or is placed after a deny policy, external traffic would be dropped. This is a common cause when VIP access fails while internal access works. Therefore, this is the most likely cause.
- ✗
There is an asymmetric routing issue or the return route is not via the FortiGate.
Why it's wrong here
Asymmetric routing can cause RPF failures, which would result in an iprope_in_check failure. However, in this scenario, the internal users can access the server, and external users cannot. If the return route were not via the FortiGate, the server's default gateway might be misconfigured, but that would affect internal users as well if they are on a different subnet. The most specific cause for external access failure with a VIP is often a missing firewall policy for the VIP or incorrect VIP configuration.
- ✗
The VIP is not configured with the correct external interface.
Why it's wrong here
If the VIP were not configured with the correct external interface, the traffic would not match the VIP at all, and debug flow would not show the iprope_in_check failure. The iprope_in_check failure indicates that the traffic matched a policy but was dropped due to a reverse path forwarding (RPF) check or similar. Therefore, the external interface configuration is likely correct, but another issue exists.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.