nerdexam
Fortinet

NSE4 · Question #258

Which of the following statements are correct regarding the configuration of a FortiGate unit as an SSL VPN gateway? (Select all that apply.)

The correct answer is C. In order to apply a portal to a user, that user must belong to an SSL VPN user group. D. The portal settings specify whether the connection will operate in web-only or tunnel mode. For FortiGate SSL VPNs, users must belong to an SSL VPN user group to be assigned a portal, and the portal settings define whether the connection operates in web-only or tunnel mode.

Submitted by katya_ua· Apr 18, 2026VPN and ZTNA

Question

Which of the following statements are correct regarding the configuration of a FortiGate unit as an SSL VPN gateway? (Select all that apply.)

Options

  • ATunnel mode can only be used if the SSL VPN user groups have at least one Host Check option
  • BThe specific routes needed to access internal resources through an SSL VPN connection in
  • CIn order to apply a portal to a user, that user must belong to an SSL VPN user group.
  • DThe portal settings specify whether the connection will operate in web-only or tunnel mode.

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    88% (23)

Why each option

For FortiGate SSL VPNs, users must belong to an SSL VPN user group to be assigned a portal, and the portal settings define whether the connection operates in web-only or tunnel mode.

ATunnel mode can only be used if the SSL VPN user groups have at least one Host Check option

Tunnel mode does not require a Host Check option; host checks are optional security measures to verify client posture but are not a prerequisite for tunnel mode functionality.

BThe specific routes needed to access internal resources through an SSL VPN connection in

While routes are needed, they are primarily configured within the SSL VPN settings or assigned to the client through the portal, not solely defined 'in the firewall policies of the VDOM' as the primary mechanism of route distribution for the VPN client.

CIn order to apply a portal to a user, that user must belong to an SSL VPN user group.Correct

In FortiGate SSL VPN configuration, users are associated with SSL VPN user groups, and these groups are then assigned specific SSL VPN portals. This structure ensures that users receive the correct access privileges and portal experience.

DThe portal settings specify whether the connection will operate in web-only or tunnel mode.Correct

Each SSL VPN portal is configured to specify the access mode, which can be 'Web Mode' (web-only access to internal web resources) or 'Tunnel Mode' (full network access via a virtual IP), or both. This setting directly controls how the client connects and what resources it can reach.

Concept tested: FortiGate SSL VPN user groups, portals, and access modes

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/181464/defining-and-assigning-ssl-vpn-portals

Topics

#SSL VPN#FortiGate Configuration#VPN Portals#User Groups

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice