"There are three modes in which SSL VPN can be deployed. These all relate to the type of client being used. The first is the clientless mode; it works at Layer 7 in the network stack, providing secure access to web resources and web-based content. This mode is commonly used for accessing content via a web browser. One drawback to this mode is that it does not provide access to TCP connections such as SSH or Telnet.
The next mode is thin client; it also works at Layer 7, known as port forwarding. This SSL mode is delivered via a Java applet downloaded from the SSL appliance when a session is established. Thin client mode provides access to services such as Telnet, Secure Shell (SSH), Simple Mail Transfer Protocol (SMTP), Internet Message Access Protocol (IMAP), and Post Office Protocol (POP3.)
The final mode is thick client mode; it works at Layer 3 and is also known as a full tunneling client. This mode provides application support through dynamically downloaded SSL client software from a VPN server appliance. This mode delivers an easy-to-support SSL VPN tunneling connection and full access to any application."