nerdexam
Fortinet

NSE4 · Question #199

Which of the following statements correctly describes how a FortiGate unit functions in Transparent mode?

The correct answer is B. An IP address is used to manage the FortiGate unit but this IP address is not associated with a. In Transparent mode, a FortiGate unit acts as a Layer 2 bridge, forwarding traffic without modifying IP addresses, and is managed via a dedicated management IP address that isn't directly bound to a physical interface for data plane operations.

Submitted by hassan_iq· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Which of the following statements correctly describes how a FortiGate unit functions in Transparent mode?

Options

  • ATo manage the FortiGate unit, one of the interfaces must be designated as the management
  • BAn IP address is used to manage the FortiGate unit but this IP address is not associated with a
  • CThe FortiGate unit must use public IP addresses on the internal and external networks.
  • DThe FortiGate unit uses private IP addresses on the internal network but hides them using

How the community answered

(33 responses)
  • B
    94% (31)
  • C
    3% (1)
  • D
    3% (1)

Why each option

In Transparent mode, a FortiGate unit acts as a Layer 2 bridge, forwarding traffic without modifying IP addresses, and is managed via a dedicated management IP address that isn't directly bound to a physical interface for data plane operations.

ATo manage the FortiGate unit, one of the interfaces must be designated as the management

While management does occur over an interface, it's not 'designated' as a management interface in the sense of having a data plane IP that traffic routes through; it's a logical management IP.

BAn IP address is used to manage the FortiGate unit but this IP address is not associated with aCorrect

In Transparent mode, the FortiGate acts as a Layer 2 bridge, inspecting traffic without routing. It needs an IP address for management, but this management IP is not associated with any specific physical interface for data plane forwarding; instead, it is a management IP that allows administrators to access the device without interfering with the bridged traffic flow.

CThe FortiGate unit must use public IP addresses on the internal and external networks.

Transparent mode operates at Layer 2 and does not perform routing or NAT, thus the concept of public/private IP addresses on internal/external networks for the FortiGate itself is not applicable to its data plane operation.

DThe FortiGate unit uses private IP addresses on the internal network but hides them using

This describes NAT/Route mode functionality, where the FortiGate uses private IP addresses internally and performs NAT, which is not how Transparent mode operates.

Concept tested: FortiGate Transparent mode functionality

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/468894/operating-modes

Topics

#FortiGate Transparent Mode#Deployment Modes#Management IP#Layer 2 Bridging

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice