nerdexam
Fortinet

NSE4 · Question #442

Which of the following statements are correct regarding SSL VPN Web-only mode? (Choose two.)

The correct answer is B. IP traffic is encapsulated over HTTPS. C. Access to internal network resources is possible from the SSL VPN portal. SSL VPN Web-only mode encapsulates IP traffic over HTTPS and allows users to access various internal network resources through a web-based portal.

Submitted by tyler.j· Apr 18, 2026VPN and ZTNA

Question

Which of the following statements are correct regarding SSL VPN Web-only mode? (Choose two.)

Options

  • AIt can only be used to connect to web services.
  • BIP traffic is encapsulated over HTTPS.
  • CAccess to internal network resources is possible from the SSL VPN portal.
  • DThe standalone FortiClient SSL VPN client CANNOT be used to establish a Web-only SSL
  • EIt is not possible to connect to SSH servers through the VPN.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    93% (28)
  • D
    3% (1)

Why each option

SSL VPN Web-only mode encapsulates IP traffic over HTTPS and allows users to access various internal network resources through a web-based portal.

AIt can only be used to connect to web services.

SSL VPN Web-only mode is not limited to only web services; its portal can also facilitate access to other types of services such as RDP, SSH, or SMB through specialized applets or links.

BIP traffic is encapsulated over HTTPS.Correct

In SSL VPN Web-only mode, the client's network traffic is encapsulated within the secure HTTPS (SSL/TLS) tunnel established with the VPN gateway, utilizing the web browser.

CAccess to internal network resources is possible from the SSL VPN portal.Correct

The SSL VPN portal in Web-only mode provides access to various internal network resources, which can include web applications, file shares, and other services often via embedded applets.

DThe standalone FortiClient SSL VPN client CANNOT be used to establish a Web-only SSL

The standalone FortiClient SSL VPN client is primarily designed for tunnel mode VPNs, and while it might access the portal, web-only mode itself is typically a clientless, browser-based connection.

EIt is not possible to connect to SSH servers through the VPN.

It is possible to connect to SSH servers through the SSL VPN portal in Web-only mode by using Java-based SSH applets or similar clientless access tools provided by the portal.

Concept tested: SSL VPN Web-only mode features

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/575308/ssl-vpn-modes

Topics

#SSL VPN#Web-only mode#VPN modes#FortiGate VPN

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice