nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #14

You are analyzing connectivity problems caused by intermediate devices blocking traffic in SSL VPN environment. In which two ways can you effectively resolve the problem? (Choose two.)

The correct answer is C. You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 D. You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP. Two effective ways to resolve SSL VPN connectivity problems caused by intermediate devices blocking traffic are: (C) Using SSL VPN tunnel mode - tunnel mode encapsulates all VPN traffic over HTTPS (TCP port 443), which is rarely blocked by firewalls or intermediate devices…

Submitted by takeshi77· Apr 18, 2026VPN

Question

You are analyzing connectivity problems caused by intermediate devices blocking traffic in SSL VPN environment. In which two ways can you effectively resolve the problem? (Choose two.)

Options

  • AYou can turn off IKE fragmentation to fix large certificate negotiation problems.
  • BYou should use IPsec to solve issues with fragment drops and large certificate exchanges.
  • CYou can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500
  • DYou can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    83% (20)

Explanation

Two effective ways to resolve SSL VPN connectivity problems caused by intermediate devices blocking traffic are: (C) Using SSL VPN tunnel mode - tunnel mode encapsulates all VPN traffic over HTTPS (TCP port 443), which is rarely blocked by firewalls or intermediate devices, whereas web mode has more limited capability; this avoids issues with blocked ESP (IP protocol 50) and UDP ports 500/4500 that IPsec requires; and (D) Configuring a hub-and-spoke topology with SSL VPN tunnels - this allows spoke sites to route traffic through a hub FortiGate using SSL VPN, bypassing intermediate devices that block UDP-based protocols. Option A is incorrect because IKE fragmentation is relevant to IPsec, not SSL VPN. Option B is incorrect because switching to IPsec would still face the same blocked UDP/ESP port issues that the question is trying to solve.

Topics

#SSL VPN#Troubleshooting#Firewall traversal#VPN protocols

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice