NSE4 · Question #318
What step is required an SSL VPN to access to an internal server using port forward mode?
The correct answer is D. Configure the client application to forward IP traffic to a Java applet proxy.. To use SSL VPN port forward mode, the client application must be configured to direct traffic through a Java applet proxy, which then tunnels the traffic to the internal server via the FortiGate.
Question
What step is required an SSL VPN to access to an internal server using port forward mode?
Options
- AConfigure the virtual IP addresses to be assigned to the SSL VPN users.
- BInstall FortiClient SSL VPN client
- CCreate a SSL VPN realm reserved for clients using port forward mode.
- DConfigure the client application to forward IP traffic to a Java applet proxy.
How the community answered
(41 responses)- A2% (1)
- B2% (1)
- D95% (39)
Why each option
To use SSL VPN port forward mode, the client application must be configured to direct traffic through a Java applet proxy, which then tunnels the traffic to the internal server via the FortiGate.
Virtual IP addresses are typically configured for tunnel mode SSL VPNs, not for port forward mode, which establishes a direct, application-specific connection.
While FortiClient can be used for SSL VPN, port forward mode often uses a web-based Java applet without requiring a full client installation.
While realms can separate user groups, creating a realm specifically "reserved for clients using port forward mode" is not a mandatory *step* for port forward mode to function, but rather an organizational choice.
In SSL VPN port forward mode, the client application needs to be configured to forward traffic destined for the internal server to a specific local port, which is then handled by the Java applet proxy that establishes the tunnel through the FortiGate.
Concept tested: SSL VPN port forward mode requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/990610/port-forward-mode
Topics
Community Discussion
No community discussion yet for this question.