Courseiva
Authentication and VPN →hardMultiple Choice

NSE4 Authentication and VPN Practice Question

An administrator runs 'diagnose vpn ssl stat' and sees 'tun-num: 5, clients: 0'. Users are unable to connect to the SSL VPN. The SSL VPN settings are correct and the certificate is valid. What could be the cause?

⚠ Common exam trap

It's easy for candidates to assume 'tun-num: 5, clients: 0' indicates a licensing or certificate issue, but the key diagnostic clue is that the tunnel interface exists (meaning the service is running) yet no clients are connected, pointing to a connectivity or port mismatch rather than a resource or authentication problem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SSL VPN is listening on a non-default port and users are connecting to the default port

The 'tun-num: 5, clients: 0' output indicates that the SSL VPN tunnel interface is up but no clients are connected. If the SSL VPN settings and certificate are correct, the most likely cause is a port mismatch: the FortiGate is configured to listen on a non-default port (e.g., 10443), but users are attempting to connect to the default SSL VPN port (443). This prevents the SSL handshake from completing, resulting in zero active clients.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiGate has reached the maximum number of SSL VPN users allowed by the license

    Why it's wrong here

    When the SSL VPN user license limit is reached, current sessions are still visible in `diagnose vpn ssl stat`; the output would show a non-zero count of active users. Since the administrator sees no clients (tun=0 or no sessions), the license limit cannot be the cause. The license limits new connections but does not erase existing ones from the statistics.

  • ✓

    The SSL VPN is listening on a non-default port and users are connecting to the default port

    Why this is correct

    The FortiGate's SSL VPN listening port is configured under `config vpn ssl settings` and defaults to 443. If it has been changed to a non-standard port like 10443, client connections attempting to reach 443 will not be accepted by the SSL VPN service, resulting in no established sessions. Thus `diagnose vpn ssl stat` correctly displays zero active tunnels because the clients are connecting to the wrong port and never complete the handshake.

  • ✗

    The SSL VPN certificate is not trusted by the client browsers

    Why it's wrong here

    An untrusted certificate generates a browser security warning, but a user can choose to accept the risk and proceed, which would allow the SSL VPN session to be established and appear in the stat output. Therefore, even with a self-signed or non-trusted certificate, you would expect to see connected clients if users have accepted the warning. The absence of any clients indicates the issue is not certificate trust but rather that connections are not reaching the SSL VPN listener at all.

  • ✗

    The SSL VPN portal is configured with 'limit-scan' scanning

    Why it's wrong here

    The `limit-scan` parameter within the SSL VPN portal configuration controls the number of times a file is scanned by antivirus, or whether scanning is skipped for certain file sizes, depending on FortiOS version—it has nothing to do with limiting concurrent users. This setting only affects file transfer scanning behavior on the portal and does not impact session establishment or the number of active tunnels. Consequently, it cannot explain why `diagnose vpn ssl stat` shows zero clients.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.