TechNuggets Academy

Firewall Policies and Network Address Translation (NAT)

Free FCP - FortiGate 7.6 Administrator practice — 6 questions on Firewall Policies and Network Address Translation (NAT), with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Firewall Policies and Network Address Translation (NAT)
An administrator enables Central NAT under Feature Visibility on a FortiGate running FortiOS 7.6 that previously used firewall policy-based (per-policy) NAT. What is the immediate effect on the existing firewall policies?
Enabling Central NAT is a global mode switch: the NAT field is removed from firewall policy configuration entirely, and all source NAT must be defined separately under Policy & Objects > Central SNAT using match criteria and IP pools. This is a common architectural change candidates must know for the exam.
Question 2 of 6 · Firewall Policies and Network Address Translation (NAT)
A service provider has a limited pool of public IP addresses but needs to support thousands of internal clients while guaranteeing that no two clients are ever assigned overlapping external port ranges, in order to reliably attribute NAT sessions during log audits. Which IP pool type should be used?
Port Block Allocation assigns each source IP a dedicated, non-overlapping block of external ports from the pool, which allows many clients to share fewer public IPs while keeping port ranges auditable and non-overlapping per client — exactly the scenario described.
Question 3 of 6 · Firewall Policies and Network Address Translation (NAT)
A VIP object maps external IP 203.0.113.10, external port 8080, to internal server 10.0.1.50 on port 80 using port forwarding. The firewall policy from WAN1 to the internal interface uses this VIP as the destination address, but the service object attached to the policy is the predefined 'HTTP' service (TCP/80). Clients connecting to 203.0.113.10:8080 get no response. What is the BEST explanation?
FortiGate evaluates the firewall policy's service field against the original (pre-DNAT) destination port seen on the wire. Since the client connects to external port 8080, the policy service must be a custom service for TCP/8080; using the predefined HTTP (TCP/80) service causes a service mismatch and the policy — and therefore the VIP translation — never applies.
Question 4 of 6 · Firewall Policies and Network Address Translation (NAT)
An administrator uses the GUI 'Move To' action to relocate firewall policy ID 15 from the bottom of the policy list to the very top. Which statement correctly describes the result in FortiOS 7.6?
Policy ID is a permanent identifier assigned at creation and used for CLI reference, logging, and API calls; it never changes when a policy is reordered. 'Move To' only changes the policy's position in the evaluation sequence (top-down order), which determines first-match behavior, not its ID.
Question 5 of 6 · Firewall Policies and Network Address Translation (NAT)
A company runs a SIP-based VoIP application behind a FortiGate performing source NAT via an IP pool in overload mode. The VoIP vendor requires that the source port seen by the external SIP server never change from what the internal phone originally used, since dynamic port translation breaks call setup. Which firewall policy CLI setting should be configured to meet this requirement?
The 'fixed-port enable' setting under 'config firewall policy' preserves the original source port during SNAT translation instead of dynamically remapping it, which is required by protocols like SIP that are sensitive to source port changes.
Question 6 of 6 · Firewall Policies and Network Address Translation (NAT)
A VIP publishes an internal web server to the internet. An administrator wants to explicitly deny access to this VIP from a specific untrusted country object using a deny policy placed above the existing allow policy. After committing the change, traffic from the blocked country is still reaching the server. What is the MOST likely missing configuration on the deny policy?
By default, deny (and some other non-accept) policies do not automatically match traffic destined for a VIP's external address because that address is normally only resolved by an allow policy referencing the VIP. The 'match-vip' CLI setting under 'config firewall policy' must be explicitly enabled on the deny policy so it evaluates and can block sessions destined to that VIP, allowing it to take precedence when placed above the allow rule.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →