NSE4 · Question #420
Regarding the use of web-only mode SSL VPN, which statement is correct?
The correct answer is C. It requires the user to have a web browser that suppports 64-bit cipher length. Web-only mode SSL VPN relies on the user's web browser supporting the necessary encryption cipher lengths to establish a secure connection.
Question
Regarding the use of web-only mode SSL VPN, which statement is correct?
Options
- AIt support SSL version 3 only.
- BIt requires a Fortinet-supplied plug-in on the web client.
- CIt requires the user to have a web browser that suppports 64-bit cipher length.
- DThe JAVA run-time environment must be installed on the client.
How the community answered
(27 responses)- A4% (1)
- C89% (24)
- D7% (2)
Why each option
Web-only mode SSL VPN relies on the user's web browser supporting the necessary encryption cipher lengths to establish a secure connection.
Modern SSL VPNs utilize secure TLS versions (like 1.2 or 1.3), not solely the outdated and vulnerable SSL version 3.
Web-only mode is clientless and typically does not require a Fortinet-supplied plug-in, unlike tunnel mode SSL VPN which often uses FortiClient.
Web-only SSL VPN establishes an encrypted session directly through the user's web browser, requiring the browser to support the specific cipher lengths (e.g., 64-bit or higher) and TLS versions negotiated for a secure connection to the FortiGate.
The JAVA run-time environment is not a requirement for web-only SSL VPN, as this mode leverages native browser capabilities rather than Java applets.
Concept tested: FortiGate SSL VPN Web-only mode requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/339482/ssl-vpn
Topics
Community Discussion
No community discussion yet for this question.