NSE4 · Question #511
Which statement is not correct regarding SSL VPN Tunnel mode?
The correct answer is C. A limited amount of IP applications are supported.. SSL VPN Tunnel mode establishes a full IP-level connection, allowing all IP-based applications to function, making the statement that it supports only a limited amount of applications incorrect.
Question
Which statement is not correct regarding SSL VPN Tunnel mode?
Options
- AIP traffic is encapsulated over HTTPS.
- BThe standalone FortiClient SSL VPN client can be used to establish a Tunnel mode SSL VPN.
- CA limited amount of IP applications are supported.
- DThe FortiGate device will dynamically assign an IP address to the SSL VPN network adapter.
How the community answered
(30 responses)- B7% (2)
- C90% (27)
- D3% (1)
Why each option
SSL VPN Tunnel mode establishes a full IP-level connection, allowing all IP-based applications to function, making the statement that it supports only a limited amount of applications incorrect.
In SSL VPN Tunnel mode, IP traffic is indeed encapsulated within the HTTPS protocol for secure transmission across the internet.
The FortiClient SSL VPN client is specifically designed to establish and manage SSL VPN connections, including Tunnel mode, providing a robust and full-featured client experience.
SSL VPN Tunnel mode installs a virtual network adapter on the client, creating a full IP-level tunnel over HTTPS that supports virtually all IP-based applications, not just a limited amount, making this statement incorrect.
FortiGate dynamically assigns an IP address to the SSL VPN virtual adapter on the client from a configured address pool, allowing the client to access internal network resources as if it were directly connected.
Concept tested: SSL VPN Tunnel mode characteristics
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469904/ssl-vpn-modes
Topics
Community Discussion
No community discussion yet for this question.