FCP_FGT_AD-7.6 · Question #118
Refer to the exhibit. FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt. What is the most likely…
The correct answer is A. The Service DNS is required in the firewall policy. DNS traffic can be allowed if user has not authenticated yet. Hostname resolution is often required by the application layer protocol (HTTP/HTTPS/FTP/Telnet) that is used to authenticate. DNS service must be explicity listed as a service in the policy.
Question
Refer to the exhibit. FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt. What is the most likely reason for this situation?
Exhibit
Options
- AThe Service DNS is required in the firewall policy.
- BThe user is using an incorrect user name.
- CNo matching user account exists for this user.
- DThe Remote-users group is not added to the Destination.
How the community answered
(48 responses)- A71% (34)
- B8% (4)
- C4% (2)
- D17% (8)
Explanation
DNS traffic can be allowed if user has not authenticated yet. Hostname resolution is often required by the application layer protocol (HTTP/HTTPS/FTP/Telnet) that is used to authenticate. DNS service must be explicity listed as a service in the policy.
Topics
Community Discussion
No community discussion yet for this question.
