nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #50

You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem? (Choose two.)

The correct answer is A. You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 B. You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP. The training is basically trying to point out the advantage of FortiGate's SSL VPN over IPSec VPN in situation where issues are caused by an intermediate device. IPsec uses ESP and UDP 500 and 4500, so where these are blocked, SSL VPN tunnel mode shines because it uses HTTPS…

Submitted by satoshi_tk· Apr 18, 2026VPN

Question

You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem? (Choose two.)

Options

  • AYou can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500
  • BYou can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP
  • CYou can turn on fragmentation to fix large certificate negotiation problems.
  • DYou should use the protocol IKEv2.

How the community answered

(18 responses)
  • A
    78% (14)
  • C
    6% (1)
  • D
    17% (3)

Explanation

The training is basically trying to point out the advantage of FortiGate's SSL VPN over IPSec VPN in situation where issues are caused by an intermediate device. IPsec uses ESP and UDP 500 and 4500, so where these are blocked, SSL VPN tunnel mode shines because it uses HTTPS (443) and TLS by default (both TCP). Again where UDP ports are blocked, SSL VPN shines (Tunnel mode Hub and Spoke) because it does not use UDP.

Topics

#VPN troubleshooting#IPsec#SSL VPN#Port blocking

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice