NSE4 · Question #3
A user logs into a SSL VPN portal and activates the tunnel mode. The administrator has enabled split tunneling. The exhibit shows the firewall policy configuration: Which static route is…
The correct answer is A. A route to a destination subnet matching the Internal_Servers address object. When split tunneling is enabled for SSL VPN, the client's routing table automatically receives routes for specific destination subnets defined in the FortiGate firewall policies that allow traffic from the SSL VPN tunnel interface.
Question
A user logs into a SSL VPN portal and activates the tunnel mode. The administrator has enabled split tunneling. The exhibit shows the firewall policy configuration:
Which static route is automatically added to the client's routing table when the tunnel mode is activated?
Exhibit
Options
- AA route to a destination subnet matching the Internal_Servers address object.
- BA route to the destination subnet configured in the tunnel mode widget.
- CA default route.
- DA route to the destination subnet configured in the SSL VPN global settings.
How the community answered
(38 responses)- A89% (34)
- C8% (3)
- D3% (1)
Why each option
When split tunneling is enabled for SSL VPN, the client's routing table automatically receives routes for specific destination subnets defined in the FortiGate firewall policies that allow traffic from the SSL VPN tunnel interface.
In SSL VPN tunnel mode with split tunneling, the FortiGate pushes specific routes to the client's routing table, which correspond to the destination networks defined in the firewall policies that permit traffic from the SSL VPN users, such as the `Internal_Servers` address object in this scenario.
While the tunnel mode widget configures general tunnel parameters, the specific routes pushed to the client for split tunneling are derived from the destination networks allowed in the firewall policy, not directly from the widget's general configuration.
A default route (0.0.0.0/0) would direct all traffic through the VPN, which is characteristic of full tunneling, not split tunneling, where only specific traffic goes through the tunnel.
SSL VPN global settings configure overall parameters and IP pools for clients, but the specific routes for split tunneling are determined by the firewall policies dictating accessible destinations through the VPN tunnel.
Concept tested: SSL VPN split tunneling routing
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/381559/split-tunneling
Topics
Community Discussion
No community discussion yet for this question.
