nerdexam
Fortinet

NSE4 · Question #310

An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)

The correct answer is B. The interface is a member of a virtual wire pair. C. The operation mode is transparent. D. The interface is a member of a zone. An interface on a FortiGate cannot be configured with an IP address if it is part of a virtual wire pair, if the FortiGate is in transparent mode, or if it is a member of a logical switch.

Submitted by amina.ke· Apr 18, 2026FortiGate Deployment and System Configuration

Question

An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)

Options

  • AThe interface has been configured for one-arm sniffer.
  • BThe interface is a member of a virtual wire pair.
  • CThe operation mode is transparent.
  • DThe interface is a member of a zone.
  • ECaptive portal is enabled in the interface.

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    84% (31)
  • E
    11% (4)

Why each option

An interface on a FortiGate cannot be configured with an IP address if it is part of a virtual wire pair, if the FortiGate is in transparent mode, or if it is a member of a logical switch.

AThe interface has been configured for one-arm sniffer.

An interface configured for one-arm sniffer mode requires an IP address for management and for the sniffer to function and collect traffic.

BThe interface is a member of a virtual wire pair.Correct

An interface configured as part of a virtual wire pair operates at Layer 2 and does not carry an IP address, as the FortiGate functions transparently like a bridge.

CThe operation mode is transparent.Correct

When the FortiGate is operating in transparent mode, most interfaces function as Layer 2 bridges and therefore do not have their own IP addresses configured.

DThe interface is a member of a zone.Correct

If an interface is a member of a software switch or hardware switch (which logically group interfaces for Layer 2 functionality, akin to a zone), the IP address is configured on the switch interface itself, not on the individual member interfaces.

ECaptive portal is enabled in the interface.

Enabling a captive portal on an interface requires that interface to have an IP address to redirect user traffic and present the portal page.

Concept tested: FortiGate interface IP address configuration restrictions

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469905/interface-types

Topics

#FortiGate interfaces#Interface configuration#Virtual Wire#Transparent Mode

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice