Skip to main content
New Member
August 18, 2026
Question

NSE 4 – WAN Interface Role and Ping Option

  • August 18, 2026
  • 2 replies
  • 90 views

Hi everyone,

I'm new to the community and I'm preparing to take the NSE 4 exam soon.

While reviewing the guide and testing some scenarios in the lab, I noticed what seems to be an inconsistency in the documentation.

The guide states:

"Administrative access options are also limited depending on the role that is set for the interface. For example, setting the interface role to 'WAN' would not display the 'Ping' option, mitigating the risk of responding to a DoS ICMP attack from the WAN."

However, even when I set the interface role to WAN, the Ping option is still available.

Has anyone experienced the same behavior or can explain why this happens? Is this a known behavior or perhaps a change in the latest version?

Thanks in advance for any clarification!

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    August 18, 2026

    I think it’s mis- or over-statement. But it might have changed with 8.0. At least with 7.4 I have the GUI still shows admin access settings.
    In any case, regardless “wan” or “lan” role setting, you can still configure everything in CLI. So it wouldn’t “mitigate the risk” anyway, it would only minimize “accidents” or “errors”.

    Toshi

    Visitor III
    August 18, 2026

    Yes, I have seen the same behavior.

    In current FortiOS versions, setting the interface role to WAN does not remove the ping option from administrative access. The interface role mainly affects how the GUI presents certain interface-related settings, while administrative access is controlled separately through “allowaccess”

    https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/574723/interface-settings

     

    For example, it is perfectly valid to have:

    config system interface

    edit "wan1"

    set role wan

    set allowaccess ping

    next

    end

     

    So, based on the actual fortios behavior and the current administration guide, that statement in the study guide appears to be outdated or simply inaccurate.

    I would consider the lab behavior you are seeing as expected. Just keep in mind that, for certification purposes, exam questions may still be based on the wording used in the official training material.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!