Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 4 - FortiOS 7.6 Administrator

Domain 2Objective 2

Configure Source NAT (SNAT) and Destination NAT (DNAT) Options in Firewall Policies NSE4-FORTIOS-ADMINISTRATOR Practice Questions (Page 2)

Part of the Firewall Policies and Authentication domain, which accounts for 20-25% of the NSE4-FORTIOS-ADMINISTRATOR exam. Fortinet does not publish an official question count, but from its 90-minute exam (~35–60 total, ~7–15 in this domain), expect 2–4 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
4concepts
20-25%of the exam

Questions 6–10

  1. 6application · medium

    An administrator is configuring a FortiGate to publish an internal email server (192.168.2.25) to the internet. The public IP is 203.0.113.80. The administrator creates a VIP with the mapped IP set to 203.0.113.80 and the mapped-to IP set to 192.168.2.25. The firewall policy from WAN to internal uses this VIP as the destination. Users report they can connect to the server, but the server sees all connections coming from the FortiGate's internal interface IP (192.168.2.1) instead of the original public source IPs. What is the most likely cause?

    Select an answer first
  2. 7expert · medium

    A FortiGate administrator is configuring DNAT for a public-facing application. The application uses TCP port 8080 externally and needs to be forwarded to an internal server on port 80. The administrator creates a VIP with the mapped IP set to 203.0.113.110 and the mapped-to IP set to 192.168.1.60. The VIP is configured with port forwarding: external port 8080 to internal port 80. The firewall policy from WAN to internal uses this VIP. Users report they can connect to the application, but the application logs show the source IP as the FortiGate's internal interface IP. What is the most likely cause?

    Select an answer first
  3. 8foundation · easy

    In a FortiGate firewall policy, which action is required to enable source NAT for traffic matching the policy?

    Select an answer first
  4. 9application · medium

    An administrator needs to publish an internal FTP server (192.168.1.20) to the internet. The public IP is 203.0.113.60. The administrator creates a VIP with the mapped IP set to 203.0.113.60 and the mapped-to IP set to 192.168.1.20. The firewall policy from WAN to internal uses this VIP. Users can connect to the FTP server, but they cannot list directories or transfer files. What is the most likely cause?

    Select an answer first
  5. 10expert · hard

    An administrator is configuring a FortiGate to publish an internal server (192.168.1.40) to the internet. The public IP is 203.0.113.90. The administrator creates a VIP with the mapped IP set to 203.0.113.90 and the mapped-to IP set to 192.168.1.40. The firewall policy from WAN to internal uses this VIP. The administrator also wants internal users to access the server using the public IP (203.0.113.90) instead of the private IP. What must be configured to allow this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE4-FORTIOS-ADMINISTRATOR” is a trademark of its owner, used for identification only.