FCP_FGT_AD-7.6 · Question #113
An employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?
The correct answer is B. SSL VPN login-timeout. When connected to SSL VPN over high latency connections, FortiGate can time out the client before the client can finish the negotiation process, such as DNS lookup and time to enter a token. Two new CLI commands under config vpn ssl settings have been added to address this. The…
Question
An employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?
Options
- ASSL VPN dtls-hello-timeout
- BSSL VPN login-timeout
- CSSL VPN
- DSSL VPN idle-timeout
How the community answered
(39 responses)- A3% (1)
- B79% (31)
- C13% (5)
- D5% (2)
Explanation
When connected to SSL VPN over high latency connections, FortiGate can time out the client before the client can finish the negotiation process, such as DNS lookup and time to enter a token. Two new CLI commands under config vpn ssl settings have been added to address this. The first command allows you to set up the login timeout, replacing the previous hard timeout value. The second command allows you to set up the maximum DTLS hello timeout for SSL VPN
Topics
Community Discussion
No community discussion yet for this question.