How is traffic routed onto an SSL VPN tunnel from the FortiGate unit side?

A.
A static route must be configured by the administrator using the ssl.root interface as the outgoing
interface.
B.
Assignment of an IP address to the client causes a host route to be added to the FortiGate unit’s
kernel routing table.
C.
A route back to the SSLVPN IP pool is automatically created on the FortiGate unit.
D.
The FortiGate unit adds a route based upon the destination address in the SSL VPN firewall policy.