NSE4 · Question #312
When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?
The correct answer is B. The FortiGate unit's internal IP address. In web-mode SSL VPN, the FortiGate acts as a proxy for internal web resource requests, using its own internal IP address as the source.
Question
When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?
Options
- AThe FortiGate unit's public IP address
- BThe FortiGate unit's internal IP address
- CThe remote user's virtual IP address
- DThe remote user's public IP address
How the community answered
(31 responses)- A3% (1)
- B87% (27)
- C3% (1)
- D6% (2)
Why each option
In web-mode SSL VPN, the FortiGate acts as a proxy for internal web resource requests, using its own internal IP address as the source.
The FortiGate's public IP address is used for external communication and VPN termination, not for initiating proxied requests to internal network resources.
When using web-mode SSL VPN, the FortiGate unit acts as a proxy, generating the HTTP request to the internal web server on behalf of the remote user, and thus uses its own internal IP address (typically the interface facing the internal network) as the source.
Virtual IP addresses are assigned to remote users in tunnel-mode SSL VPN for direct network access, whereas web-mode is a clientless proxy solution that does not assign virtual IPs.
The remote user's public IP address is the initial source of the traffic to the FortiGate, but the FortiGate then proxies the request to the internal server using its own internal IP.
Concept tested: FortiGate SSL VPN web-mode proxying
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/76807/ssl-vpn-types
Topics
Community Discussion
No community discussion yet for this question.