nerdexam
Fortinet

NSE4 · Question #3

A user logs into a SSL VPN portal and activates the tunnel mode. The administrator has enabled split tunneling. The exhibit shows the firewall policy configuration: Which static route is…

The correct answer is A. A route to a destination subnet matching the Internal_Servers address object. When split tunneling is enabled for SSL VPN, the client's routing table automatically receives routes for specific destination subnets defined in the FortiGate firewall policies that allow traffic from the SSL VPN tunnel interface.

Submitted by parkjh· Apr 18, 2026VPN and Routing

Question

A user logs into a SSL VPN portal and activates the tunnel mode. The administrator has enabled split tunneling. The exhibit shows the firewall policy configuration:

Which static route is automatically added to the client's routing table when the tunnel mode is activated?

Exhibit

NSE4 question #3 exhibit

Options

  • AA route to a destination subnet matching the Internal_Servers address object.
  • BA route to the destination subnet configured in the tunnel mode widget.
  • CA default route.
  • DA route to the destination subnet configured in the SSL VPN global settings.

How the community answered

(38 responses)
  • A
    89% (34)
  • C
    8% (3)
  • D
    3% (1)

Why each option

When split tunneling is enabled for SSL VPN, the client's routing table automatically receives routes for specific destination subnets defined in the FortiGate firewall policies that allow traffic from the SSL VPN tunnel interface.

AA route to a destination subnet matching the Internal_Servers address object.Correct

In SSL VPN tunnel mode with split tunneling, the FortiGate pushes specific routes to the client's routing table, which correspond to the destination networks defined in the firewall policies that permit traffic from the SSL VPN users, such as the `Internal_Servers` address object in this scenario.

BA route to the destination subnet configured in the tunnel mode widget.

While the tunnel mode widget configures general tunnel parameters, the specific routes pushed to the client for split tunneling are derived from the destination networks allowed in the firewall policy, not directly from the widget's general configuration.

CA default route.

A default route (0.0.0.0/0) would direct all traffic through the VPN, which is characteristic of full tunneling, not split tunneling, where only specific traffic goes through the tunnel.

DA route to the destination subnet configured in the SSL VPN global settings.

SSL VPN global settings configure overall parameters and IP pools for clients, but the specific routes for split tunneling are determined by the firewall policies dictating accessible destinations through the VPN tunnel.

Concept tested: SSL VPN split tunneling routing

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/381559/split-tunneling

Topics

#SSL VPN#Split Tunneling#Routing Table#Firewall Policies

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice