Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

A FortiGate is configured as an SSL VPN server with tunnel mode. Remote users authenticate successfully, but after connecting they cannot reach any internal subnet. The administrator verifies that the SSL VPN firewall policy allows the tunnel interface and that the internal routes exist. Which SSL VPN configuration setting must be checked next to ensure that the correct routes are pushed to the clients?

⚠ Common exam trap

The trap here is assuming that enabling split tunneling automatically defines which subnets are routed through the tunnel, when in fact the Routing Address setting must be populated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the 'Routing Address' in the SSL VPN portal to include the internal subnets.

In SSL VPN tunnel mode, the FortiGate pushes routes to the client based on the 'Routing Address' defined in the SSL VPN portal. If this setting is empty or does not include the internal subnets, the client will not have routes for those networks, even though the tunnel is up and the firewall policy permits traffic. Verifying and correcting the Routing Address is the direct solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the 'Routing Address' in the SSL VPN portal to include the internal subnets.

    Why this is correct

    In tunnel mode, the SSL VPN portal's 'Routing Address' setting defines the destination subnets that are pushed to the client and routed through the tunnel. If it is empty or incorrect, clients will not have routes for internal networks, causing the described failure. This setting is the primary method to control which subnets are reachable over the SSL VPN tunnel.

  • ✗

    Enable 'client-certificate' authentication in the SSL VPN settings.

    Why it's wrong here

    Client certificate authentication is an authentication method, not a routing mechanism. Enabling it would require users to present certificates and would not affect the routes pushed to the client. Since users already authenticate successfully, changing authentication will not resolve the inability to reach internal subnets after connection.

  • ✗

    Set the SSL VPN to use 'web mode' instead of 'tunnel mode'.

    Why it's wrong here

    Web mode provides browser-based access to specific services, not full network-level access. Switching to web mode would not give users the ability to reach internal subnets as if they were on the network. The scenario describes a tunnel mode configuration where full IP access is expected, so changing the mode is inappropriate and would not fix routing.

  • ✗

    Enable 'split-tunneling' in the SSL VPN portal settings.

    Why it's wrong here

    Split tunneling controls whether all traffic or only specific destination subnets are sent through the tunnel. While it affects routing on the client, enabling it does not automatically push the correct internal routes. The administrator still must define which subnets are routed through the tunnel, and split tunneling alone does not guarantee reachability to internal resources.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.