nerdexam
Fortinet

NSE4 · Question #511

Which statement is not correct regarding SSL VPN Tunnel mode?

The correct answer is C. A limited amount of IP applications are supported.. SSL VPN Tunnel mode establishes a full IP-level connection, allowing all IP-based applications to function, making the statement that it supports only a limited amount of applications incorrect.

Submitted by femi9· Apr 18, 2026VPN and Routing

Question

Which statement is not correct regarding SSL VPN Tunnel mode?

Options

  • AIP traffic is encapsulated over HTTPS.
  • BThe standalone FortiClient SSL VPN client can be used to establish a Tunnel mode SSL VPN.
  • CA limited amount of IP applications are supported.
  • DThe FortiGate device will dynamically assign an IP address to the SSL VPN network adapter.

How the community answered

(30 responses)
  • B
    7% (2)
  • C
    90% (27)
  • D
    3% (1)

Why each option

SSL VPN Tunnel mode establishes a full IP-level connection, allowing all IP-based applications to function, making the statement that it supports only a limited amount of applications incorrect.

AIP traffic is encapsulated over HTTPS.

In SSL VPN Tunnel mode, IP traffic is indeed encapsulated within the HTTPS protocol for secure transmission across the internet.

BThe standalone FortiClient SSL VPN client can be used to establish a Tunnel mode SSL VPN.

The FortiClient SSL VPN client is specifically designed to establish and manage SSL VPN connections, including Tunnel mode, providing a robust and full-featured client experience.

CA limited amount of IP applications are supported.Correct

SSL VPN Tunnel mode installs a virtual network adapter on the client, creating a full IP-level tunnel over HTTPS that supports virtually all IP-based applications, not just a limited amount, making this statement incorrect.

DThe FortiGate device will dynamically assign an IP address to the SSL VPN network adapter.

FortiGate dynamically assigns an IP address to the SSL VPN virtual adapter on the client from a configured address pool, allowing the client to access internal network resources as if it were directly connected.

Concept tested: SSL VPN Tunnel mode characteristics

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469904/ssl-vpn-modes

Topics

#SSL VPN#Tunnel Mode#FortiClient

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice