NSE4 · Question #258
Which of the following statements are correct regarding the configuration of a FortiGate unit as an SSL VPN gateway? (Select all that apply.)
The correct answer is C. In order to apply a portal to a user, that user must belong to an SSL VPN user group. D. The portal settings specify whether the connection will operate in web-only or tunnel mode. For FortiGate SSL VPNs, users must belong to an SSL VPN user group to be assigned a portal, and the portal settings define whether the connection operates in web-only or tunnel mode.
Question
Which of the following statements are correct regarding the configuration of a FortiGate unit as an SSL VPN gateway? (Select all that apply.)
Options
- ATunnel mode can only be used if the SSL VPN user groups have at least one Host Check option
- BThe specific routes needed to access internal resources through an SSL VPN connection in
- CIn order to apply a portal to a user, that user must belong to an SSL VPN user group.
- DThe portal settings specify whether the connection will operate in web-only or tunnel mode.
How the community answered
(26 responses)- A8% (2)
- B4% (1)
- C88% (23)
Why each option
For FortiGate SSL VPNs, users must belong to an SSL VPN user group to be assigned a portal, and the portal settings define whether the connection operates in web-only or tunnel mode.
Tunnel mode does not require a Host Check option; host checks are optional security measures to verify client posture but are not a prerequisite for tunnel mode functionality.
While routes are needed, they are primarily configured within the SSL VPN settings or assigned to the client through the portal, not solely defined 'in the firewall policies of the VDOM' as the primary mechanism of route distribution for the VPN client.
In FortiGate SSL VPN configuration, users are associated with SSL VPN user groups, and these groups are then assigned specific SSL VPN portals. This structure ensures that users receive the correct access privileges and portal experience.
Each SSL VPN portal is configured to specify the access mode, which can be 'Web Mode' (web-only access to internal web resources) or 'Tunnel Mode' (full network access via a virtual IP), or both. This setting directly controls how the client connects and what resources it can reach.
Concept tested: FortiGate SSL VPN user groups, portals, and access modes
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/181464/defining-and-assigning-ssl-vpn-portals
Topics
Community Discussion
No community discussion yet for this question.