nerdexam
Fortinet

NSE4 · Question #478

Review to the network topology in the exhibit. The workstation, 172.16.1.1/24, connects to port2 of the FortiGate device, and the ISP router, 172.16.1.2, connects to port1. Without changing IP…

The correct answer is A. At least one firewall policy from port2 to port1 to allow outgoing traffic. D. The FortiGate devices configured in transparent mode. To allow workstation traffic to the Internet without IP address changes, a firewall policy from port2 to port1 is required, and the FortiGate must be configured in transparent mode.

Submitted by femi9· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Review to the network topology in the exhibit. The workstation, 172.16.1.1/24, connects to port2 of the FortiGate device, and the ISP router, 172.16.1.2, connects to port1. Without changing IP addressing, which configuration changes are required to properly forward users traffic to the Internet? (Choose two)

Exhibit

NSE4 question #478 exhibit

Options

  • AAt least one firewall policy from port2 to port1 to allow outgoing traffic.
  • BA default route configured in the FortiGuard devices pointing to the ISP's router.
  • CStatic or dynamic IP addresses in both ForitGate interfaces port1 and port2.
  • DThe FortiGate devices configured in transparent mode.

How the community answered

(32 responses)
  • A
    84% (27)
  • B
    9% (3)
  • C
    6% (2)

Why each option

To allow workstation traffic to the Internet without IP address changes, a firewall policy from port2 to port1 is required, and the FortiGate must be configured in transparent mode.

AAt least one firewall policy from port2 to port1 to allow outgoing traffic.Correct

A firewall policy is essential in any FortiGate configuration to explicitly allow traffic from the internal network (port2) to the external network (port1/ISP) to pass through the device. Without a policy, all traffic is implicitly denied.

BA default route configured in the FortiGuard devices pointing to the ISP's router.

A default route is typically configured when the FortiGate acts as a router in NAT/Route mode, but transparent mode is more appropriate given the constraint of 'Without changing IP addressing' and the single subnet.

CStatic or dynamic IP addresses in both ForitGate interfaces port1 and port2.

When the FortiGate is in transparent mode, its interfaces typically do not require static or dynamic IP addresses for traffic forwarding, as it operates at Layer 2.

DThe FortiGate devices configured in transparent mode.Correct

The question states 'Without changing IP addressing' and shows both workstation and ISP router on the same subnet. For the FortiGate to forward traffic between devices on the same subnet without acting as a router, it must be in transparent mode, effectively bridging the two interfaces.

Concept tested: FortiGate transparent mode and firewall policies

Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guide/339239/switching-between-nat-route-and-transparent-mode

Topics

#Firewall Policies#Transparent Mode#FortiGate Operation Modes#Network Topology Analysis

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice