LFCS Networking Practice Question
A Linux server has two interfaces, ens5 (203.0.113.10/24) and ens6 (10.20.0.0/24 gateway for internal clients). Internal clients must reach the internet through ens5. The administrator has enabled net.ipv4.ip_forward=1 and configured NAT on ens5, but clients still cannot reach external hosts. Which two additional checks are most likely to resolve the problem? (Choose two.)
⚠ Common exam trap
The trap here is assuming that enabling ip_forward and writing any NAT rule is sufficient, when firewall forwarding policy and precise NAT match criteria must both be correct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm that the MASQUERADE or SNAT rule matches the outbound interface and source subnet correctly.
When IP forwarding and NAT appear configured but clients still fail, the two most common culprits are a restrictive FORWARD chain that drops inter-interface traffic and a NAT rule whose interface or source match is wrong. Both must be verified because either alone prevents end-to-end connectivity for the internal subnet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confirm that the MASQUERADE or SNAT rule matches the outbound interface and source subnet correctly.
Why this is correct
A NAT rule that references the wrong interface, such as the internal one instead of ens5, or an incorrect source range, will not translate the clients' private addresses. External hosts then have no route back to the 10.20.0.0/24 network, so replies never arrive. Verifying the rule's match criteria is essential when NAT appears configured but does not function.
- ✗
Disable the reverse path filter by setting net.ipv4.conf.all.rp_filter to 2.
Why it's wrong here
Setting rp_filter to 2 enables loose reverse path filtering, which is a diagnostic step rather than a fix. While strict reverse path filtering can drop asymmetric traffic, this scenario describes a straightforward two-interface gateway, so it is unlikely to be the root cause. Changing rp_filter is not one of the two most probable remediations.
- ✗
Add a static route on the internal clients pointing to the public internet address 203.0.113.10 as the next hop.
Why it's wrong here
Internal clients should use the server's internal address on ens6 as their default gateway, not the public address. Routing through the public interface address is not reachable from the private subnet without additional configuration. This change would not fix the described problem and could introduce new routing errors.
- ✓
Verify that the FORWARD chain policy or rules permit traffic between ens6 and ens5.
Why this is correct
Enabling ip_forward alone does not bypass packet filtering. On hosts with a default FORWARD policy of DROP, forwarded packets between the internal and external interfaces are silently discarded. Adding accept rules for the relevant interfaces, or adjusting the policy, is a common fix when routing and NAT are correct but forwarding still fails.
- ✗
Ensure that the server's default route points to the upstream router on the ens5 network.
Why it's wrong here
While a correct default route is necessary for the server itself to reach external networks, the scenario states that NAT is configured on ens5, implying the server already has working external connectivity. The described symptom is clients failing, not the server. The two most probable causes are forwarding filter rules and NAT match criteria.
Visual reference
Go deeper
Related to this question
About these practice questions
This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.