Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

Which TWO features are required to implement an always-on SSL VPN tunnel with FortiGate that automatically reconnects when the user's network changes?

⚠ Common exam trap

A common mix-up: candidates confuse DTLS (which improves performance but is optional) with a requirement for always-on connectivity, or they mistakenly think split tunneling is needed for automatic reconnection, when in fact the core requirements are tunnel mode and the auto-connect client setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tunnel mode enabled

Option A (Tunnel mode enabled) is correct because an always-on SSL VPN requires a full tunnel-mode connection, which routes all traffic through the FortiGate and supports the persistent, automatically reconnecting VPN interface; web-mode portals are session-based and cannot provide an always-on tunnel. Option C (Auto-connect setting in FortiClient) is correct because FortiClient's auto-connect feature establishes the SSL VPN tunnel at startup and automatically re-establishes it when the underlying network changes, which is exactly the always-on behavior described. Option B (DTLS enabled) is not required, since DTLS only optimizes transport performance and the tunnel can reconnect over TLS. Option D (Web mode portal) is not required because web mode is a clientless, browser-based access method that cannot deliver an always-on tunnel. Option E (Split tunneling configured) is not required because split tunneling only controls which traffic is routed through the tunnel and does not enable automatic reconnection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tunnel mode enabled

    Why this is correct

    Tunnel mode is mandatory because it encapsulates all traffic in the SSL VPN tunnel, giving the client a persistent virtual interface that survives underlying network changes. This satisfies the always-on requirement: when the user's physical link switches, the tunnel re-establishes automatically rather than dropping to split-tunnel behaviour.

  • ✗

    DTLS enabled

    Why it's wrong here

    DTLS accelerates SSL VPN data transport over UDP but does not provide always-on reconnection or network-change detection. It is tempting because DTLS is commonly enabled on SSL VPN portals for performance. Automatic reconnection requires FortiClient's always-up VPN setting, which re-establishes the tunnel when the underlying interface changes.

  • ✓

    Auto-connect setting in FortiClient

    Why this is correct

    Auto-connect in FortiClient establishes the SSL VPN tunnel at startup and re-establishes it whenever the underlying network interface changes, satisfying the always-on reconnection constraint. Combined with the FortiGate-side always-up configuration, it removes manual user intervention, so the tunnel recovers automatically after Wi-Fi or wired transitions.

  • ✗

    Web mode portal

    Why it's wrong here

    Web mode delivers portal-based access through a browser, which cannot maintain a persistent tunnel or reconnect automatically. It is tempting because web mode is a standard SSL VPN access method, but it is session-oriented and stateless between requests. Always-on requires tunnel mode with FortiClient, not browser-based portal access.

  • ✗

    Split tunneling configured

    Why it's wrong here

    Split tunnelling controls which destinations bypass the tunnel; it has no bearing on reconnection behaviour. It is tempting because split tunnelling is frequently configured alongside SSL VPN for performance, but it only affects routing of traffic, not detection of network changes or tunnel re-establishment. Always-on depends on FortiClient's reconnect settings.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.