View all questions & answers for the NSE 4 - FortiOS 7.6 Administrator Exam Materials exam


NSE 4 - FortiOS 7.6 Administrator Exam Materials-Question 68 Discussion

Refer to the exhibits. A diagram of a FortiGate device connected to the network VIP object and firewall policy configurations are shown. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. If the host 100.65.1.111 sends a TCP SYN packet on port 443 to 100.65.0.200, what will the source address, destination address, and destination port of the packet be at the time FortiGate forwards the packet to the destination? (Choose one answer)

  • A. 10.0.11.254, 10.0.15.50, and 4443, respectively
  • B. 100.65.1.111, 10.0.11.50, and 443, respectively
  • C. 10.0.11.254, 100.65.0.200, and 443, respectively
  • D. 100.65.1.111, 10.0.11.50, and 4443, respectively
Correct Answer: D

Brave-Dump Clients Votes

D 66.67%
A 33.33%

Comments



Ashequr Rahman Khan 2026-03-20 06:21:07

Selected Answers: A


Please explain why the source address will not be changed to 10.0.11.254? Is it because NAT is disabled in Web_Server_Access(2) policy?
  • abdulrahman 2026-03-25 05:58:14
    yes the source wont change because of Source NAT disabled in policy 2.


abdulrahman 2026-03-25 06:00:32

Selected Answers: D


policy NAT affect the Source address while the Virtual IP mapping act as destination NAT and affect the destination and has nothing to do with the NAT being disabled in the policy because the mapping happen before applying the policy.


onder 2026-03-28 19:22:16

Selected Answers: D


second policy will be applied.