nerdexam
Fortinet

NSE4 · Question #367

Acme Web Hosting is replacing one of their firewalls with a FortiGate. It must be able to apply port forwarding to their back-end web servers while blocking virus uploads and TCP SYN floods from…

The correct answer is A. NAT/route. To perform port forwarding, block viruses, and protect against SYN floods, the FortiGate should operate in NAT/route mode, enabling full Layer 3 functionality and comprehensive security features.

Submitted by akirajp· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Acme Web Hosting is replacing one of their firewalls with a FortiGate. It must be able to apply port forwarding to their back-end web servers while blocking virus uploads and TCP SYN floods from attackers. Which operation mode is the best choice for these requirements?

Options

  • ANAT/route
  • BNAT mode with an interface in one-arm sniffer mode
  • CTransparent mode
  • DNo appropriate operation mode exists

How the community answered

(20 responses)
  • A
    85% (17)
  • B
    10% (2)
  • D
    5% (1)

Why each option

To perform port forwarding, block viruses, and protect against SYN floods, the FortiGate should operate in NAT/route mode, enabling full Layer 3 functionality and comprehensive security features.

ANAT/routeCorrect

NAT/route mode (or NAT mode) allows the FortiGate to function as a Layer 3 gateway, enabling Network Address Translation (NAT) for port forwarding and providing full access to advanced security features like antivirus and IPS for robust threat protection.

BNAT mode with an interface in one-arm sniffer mode

NAT mode with an interface in one-arm sniffer mode is primarily for monitoring network traffic passively and does not support active blocking, port forwarding, or acting as a security enforcement point.

CTransparent mode

Transparent mode (or Bridge mode) operates at Layer 2, acting as a 'bump in the wire' without performing NAT or port forwarding, thus not meeting the requirement for port forwarding.

DNo appropriate operation mode exists

NAT/route mode perfectly suits the requirements for port forwarding and advanced threat protection.

Concept tested: FortiGate operation modes and capabilities

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/500078/operational-modes

Topics

#Operation Modes#NAT#Port Forwarding#Security Profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice