nerdexam
Fortinet

NSE4 · Question #176

A FortiGate unit can create a secure connection to a client using SSL VPN in tunnel mode. Which of the following statements are correct regarding the use of tunnel mode SSL VPN? (Select all that apply

The correct answer is A. Split tunneling can be enabled when using tunnel mode SSL VPN. B. Software must be downloaded to the web client to be able to use a tunnel mode SSL VPN. C. Users attempting to create a tunnel mode SSL VPN connection must be members of a configured E. The source IP address used by the client for the tunnel mode SSL VPN is assigned by the. SSL VPN tunnel mode on FortiGate supports split tunneling, requires software download (typically FortiClient) for web-initiated connections, necessitates user group membership for authorization, and assigns client IP addresses from the FortiGate.

Submitted by hans_de· Apr 18, 2026VPN and Routing

Question

A FortiGate unit can create a secure connection to a client using SSL VPN in tunnel mode. Which of the following statements are correct regarding the use of tunnel mode SSL VPN? (Select all that apply.)

Options

  • ASplit tunneling can be enabled when using tunnel mode SSL VPN.
  • BSoftware must be downloaded to the web client to be able to use a tunnel mode SSL VPN.
  • CUsers attempting to create a tunnel mode SSL VPN connection must be members of a configured
  • DTunnel mode SSL VPN requires the FortiClient software to be installed on the user's computer.
  • EThe source IP address used by the client for the tunnel mode SSL VPN is assigned by the

How the community answered

(36 responses)
  • A
    92% (33)
  • D
    8% (3)

Why each option

SSL VPN tunnel mode on FortiGate supports split tunneling, requires software download (typically FortiClient) for web-initiated connections, necessitates user group membership for authorization, and assigns client IP addresses from the FortiGate.

ASplit tunneling can be enabled when using tunnel mode SSL VPN.Correct

Split tunneling is a configurable feature in SSL VPN tunnel mode, allowing some traffic to bypass the VPN tunnel for local internet access while other traffic (e.g., corporate network-bound) uses the tunnel.

BSoftware must be downloaded to the web client to be able to use a tunnel mode SSL VPN.Correct

When connecting to an SSL VPN tunnel mode from a web portal without a pre-installed client, the necessary software (like FortiClient) must be downloaded to establish the VPN tunnel.

CUsers attempting to create a tunnel mode SSL VPN connection must be members of a configuredCorrect

Users must be members of a configured firewall user group that is authorized for SSL VPN access to successfully establish a tunnel mode connection.

DTunnel mode SSL VPN requires the FortiClient software to be installed on the user's computer.

While FortiClient is the primary and recommended client for SSL VPN tunnel mode, some scenarios might allow for temporary client components or specific browser plugins to establish a tunnel without a full FortiClient installation.

EThe source IP address used by the client for the tunnel mode SSL VPN is assigned by theCorrect

The FortiGate unit assigns an internal IP address to the connected SSL VPN client from a defined IP address pool, which the client uses for communication within the VPN tunnel.

Concept tested: FortiGate SSL VPN tunnel mode features

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/765057/ssl-vpn-introduction

Topics

#SSL VPN#Tunnel Mode#FortiClient#VPN Client

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice