NSE 5 – Network Security Analyst — Question 9
A client can establish a secure connection to a corporate network using SSL VPN in tunnel mode.
Which of the following statements are correct regarding the use of tunnel mode SSL VPN? (Select all that apply.)
Answer options
- A. Split tunneling can be enabled when using tunnel mode SSL VPN.
- B. Client software is required to be able to use a tunnel mode SSL VPN.
- C. Users attempting to create a tunnel mode SSL VPN connection must be authenticated by at least one SSL VPN policy.
- D. The source IP address used by the client for the tunnel mode SSL VPN is assigned by the FortiGate unit.
Correct answer: A, B, C, D
Explanation
All options A, B, C, and D are correct. Split tunneling is indeed possible with tunnel mode SSL VPN, client software is necessary for the connection, user authentication through SSL VPN policy is required, and the source IP address is allocated by the FortiGate unit for the client during the SSL VPN session.