nerdexam
Fortinet

NSE4 · Question #4

Regarding tunnel-mode SSL VPN, which three statements are correct? (Choose three.)

The correct answer is A. Split tunneling is supported. B. It requires the installation of a VPN client. E. An SSL VPN IP address is dynamically assigned to the client by the FortiGate unit. SSL VPN tunnel mode supports split tunneling, requires a dedicated VPN client for operation, and dynamically assigns an IP address to the connected client from the FortiGate.

Submitted by lukas.cz· Apr 18, 2026VPN and ZTNA

Question

Regarding tunnel-mode SSL VPN, which three statements are correct? (Choose three.)

Options

  • ASplit tunneling is supported.
  • BIt requires the installation of a VPN client.
  • CIt requires the use of an Internet browser.
  • DIt does not support traffic from third-party network applications.
  • EAn SSL VPN IP address is dynamically assigned to the client by the FortiGate unit.

How the community answered

(50 responses)
  • A
    94% (47)
  • C
    2% (1)
  • D
    4% (2)

Why each option

SSL VPN tunnel mode supports split tunneling, requires a dedicated VPN client for operation, and dynamically assigns an IP address to the connected client from the FortiGate.

ASplit tunneling is supported.Correct

SSL VPN tunnel mode can be configured to use split tunneling, allowing only specific traffic destined for the corporate network to pass through the VPN tunnel while other traffic uses the client's local internet connection.

BIt requires the installation of a VPN client.Correct

To establish a network-layer tunnel for SSL VPN in tunnel mode, a dedicated VPN client application (like FortiClient) must typically be installed and used on the end-user's workstation.

CIt requires the use of an Internet browser.

While an initial portal login might use a browser, the actual operation of SSL VPN in tunnel mode requires a dedicated client application, not continuous use of an Internet browser, which is more characteristic of web-mode SSL VPN.

DIt does not support traffic from third-party network applications.

SSL VPN tunnel mode creates a virtual network interface on the client, enabling all network applications on the client to send traffic through the secure tunnel, not just specific or first-party applications.

EAn SSL VPN IP address is dynamically assigned to the client by the FortiGate unit.Correct

Upon successful connection in SSL VPN tunnel mode, the FortiGate unit dynamically assigns an IP address to the client's virtual network adapter from a pre-configured IP address pool.

Concept tested: SSL VPN tunnel mode characteristics

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/381559/split-tunneling

Topics

#SSL VPN#Tunnel Mode#VPN Client#Split Tunneling

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice