FCP_FGT_AD-7.6 · Question #14
You are analyzing connectivity problems caused by intermediate devices blocking traffic in SSL VPN environment. In which two ways can you effectively resolve the problem? (Choose two.)
The correct answer is C. You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 D. You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP. Two effective ways to resolve SSL VPN connectivity problems caused by intermediate devices blocking traffic are: (C) Using SSL VPN tunnel mode - tunnel mode encapsulates all VPN traffic over HTTPS (TCP port 443), which is rarely blocked by firewalls or intermediate devices…
Question
You are analyzing connectivity problems caused by intermediate devices blocking traffic in SSL VPN environment. In which two ways can you effectively resolve the problem? (Choose two.)
Options
- AYou can turn off IKE fragmentation to fix large certificate negotiation problems.
- BYou should use IPsec to solve issues with fragment drops and large certificate exchanges.
- CYou can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500
- DYou can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP
How the community answered
(24 responses)- A13% (3)
- B4% (1)
- C83% (20)
Explanation
Two effective ways to resolve SSL VPN connectivity problems caused by intermediate devices blocking traffic are: (C) Using SSL VPN tunnel mode - tunnel mode encapsulates all VPN traffic over HTTPS (TCP port 443), which is rarely blocked by firewalls or intermediate devices, whereas web mode has more limited capability; this avoids issues with blocked ESP (IP protocol 50) and UDP ports 500/4500 that IPsec requires; and (D) Configuring a hub-and-spoke topology with SSL VPN tunnels - this allows spoke sites to route traffic through a hub FortiGate using SSL VPN, bypassing intermediate devices that block UDP-based protocols. Option A is incorrect because IKE fragmentation is relevant to IPsec, not SSL VPN. Option B is incorrect because switching to IPsec would still face the same blocked UDP/ESP port issues that the question is trying to solve.
Topics
Community Discussion
No community discussion yet for this question.