nerdexam
Fortinet

NSE4 · Question #198

Which of the following statements is correct regarding a FortiGate unit operating in NAT/Route mode?

The correct answer is C. The FortiGate unit commonly uses private IP addresses on the internal network but hides them. In NAT/Route mode, a FortiGate unit functions as a router, typically using private IP addresses for internal networks and performing Network Address Translation (NAT) to hide these private IPs when communicating with external public networks.

Submitted by katya_ua· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Which of the following statements is correct regarding a FortiGate unit operating in NAT/Route mode?

Options

  • AThe FortiGate unit requires only a single IP address for receiving updates and configuring from a
  • BThe FortiGate unit must use public IP addresses on both the internal and external networks.
  • CThe FortiGate unit commonly uses private IP addresses on the internal network but hides them
  • DThe FortiGate unit uses only DHCP-assigned IP addresses on the internal network.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    93% (28)

Why each option

In NAT/Route mode, a FortiGate unit functions as a router, typically using private IP addresses for internal networks and performing Network Address Translation (NAT) to hide these private IPs when communicating with external public networks.

AThe FortiGate unit requires only a single IP address for receiving updates and configuring from a

In NAT/Route mode, the FortiGate acts as a router with an IP address on each connected interface, not just a single IP for all functions.

BThe FortiGate unit must use public IP addresses on both the internal and external networks.

Using public IP addresses on both internal and external networks defeats the purpose of NAT and is not a common or best practice configuration for internal LANs.

CThe FortiGate unit commonly uses private IP addresses on the internal network but hides themCorrect

In NAT/Route mode, the FortiGate operates as a Layer 3 device and a NAT gateway. It commonly assigns private IP addresses to devices on the internal network and performs Source NAT (SNAT) when traffic leaves the internal network for the internet, effectively hiding the internal private IP addresses behind one or more public IP addresses of the FortiGate's external interface.

DThe FortiGate unit uses only DHCP-assigned IP addresses on the internal network.

While the internal network can use DHCP-assigned IP addresses, it is not the *only* method; static IP addressing is also commonly used.

Concept tested: FortiGate NAT/Route mode functionality

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/468894/operating-modes

Topics

#NAT/Route Mode#IP Addressing#Network Address Translation#Private IP Addresses

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice