NSE7 Advanced VPN and Zero Trust Practice Question
Which TWO features are required to implement an always-on SSL VPN tunnel with FortiGate that automatically reconnects when the user's network changes?
⚠ Common exam trap
A common mix-up: candidates confuse DTLS (which improves performance but is optional) with a requirement for always-on connectivity, or they mistakenly think split tunneling is needed for automatic reconnection, when in fact the core requirements are tunnel mode and the auto-connect client setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tunnel mode enabled
Option A (Tunnel mode enabled) is correct because an always-on SSL VPN requires a full tunnel-mode connection, which routes all traffic through the FortiGate and supports the persistent, automatically reconnecting VPN interface; web-mode portals are session-based and cannot provide an always-on tunnel. Option C (Auto-connect setting in FortiClient) is correct because FortiClient's auto-connect feature establishes the SSL VPN tunnel at startup and automatically re-establishes it when the underlying network changes, which is exactly the always-on behavior described. Option B (DTLS enabled) is not required, since DTLS only optimizes transport performance and the tunnel can reconnect over TLS. Option D (Web mode portal) is not required because web mode is a clientless, browser-based access method that cannot deliver an always-on tunnel. Option E (Split tunneling configured) is not required because split tunneling only controls which traffic is routed through the tunnel and does not enable automatic reconnection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tunnel mode enabled
Why this is correct
Tunnel mode is mandatory because it encapsulates all traffic in the SSL VPN tunnel, giving the client a persistent virtual interface that survives underlying network changes. This satisfies the always-on requirement: when the user's physical link switches, the tunnel re-establishes automatically rather than dropping to split-tunnel behaviour.
- ✗
DTLS enabled
Why it's wrong here
DTLS accelerates SSL VPN data transport over UDP but does not provide always-on reconnection or network-change detection. It is tempting because DTLS is commonly enabled on SSL VPN portals for performance. Automatic reconnection requires FortiClient's always-up VPN setting, which re-establishes the tunnel when the underlying interface changes.
- ✓
Auto-connect setting in FortiClient
Why this is correct
Auto-connect in FortiClient establishes the SSL VPN tunnel at startup and re-establishes it whenever the underlying network interface changes, satisfying the always-on reconnection constraint. Combined with the FortiGate-side always-up configuration, it removes manual user intervention, so the tunnel recovers automatically after Wi-Fi or wired transitions.
- ✗
Web mode portal
Why it's wrong here
Web mode delivers portal-based access through a browser, which cannot maintain a persistent tunnel or reconnect automatically. It is tempting because web mode is a standard SSL VPN access method, but it is session-oriented and stateless between requests. Always-on requires tunnel mode with FortiClient, not browser-based portal access.
- ✗
Split tunneling configured
Why it's wrong here
Split tunnelling controls which destinations bypass the tunnel; it has no bearing on reconnection behaviour. It is tempting because split tunnelling is frequently configured alongside SSL VPN for performance, but it only affects routing of traffic, not detection of network changes or tunnel re-establishment. Always-on depends on FortiClient's reconnect settings.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.