FCSS_LED_AR-7.6 · Question #25
Refer to the exhibits. Examine the network diagram and packet capture shown in the exhibit. During packet capture analysis, a RADIUS Access-Request packet was detected being sent from FortiSwitch to…
The correct answer is C. MAC address-based authentication is being used for the client through MAC Authentication. The RADIUS Access-Request shows the client's MAC address in the User-Name attribute, which is the standard behavior when MAC Authentication Bypass (MAB) is used. Since the client is a non-802.1X device, FortiSwitch falls back to MAB, using the MAC address as the user identifier…
Question
Refer to the exhibits. Examine the network diagram and packet capture shown in the exhibit. During packet capture analysis, a RADIUS Access-Request packet was detected being sent from FortiSwitch to FortiAuthenticator and passing through FortiGate. The capture shows that the User-Name attribute in the RADIUS Access-Request packet contains the client MAC address. Why is the client MAC address contained in the User-Name attribute of the RADIUS Access- Request packet?
Exhibits
Options
- AFortiAuthenticator is authenticating the client based on the device hostname.
- BFortiAuthenticator is performing machine authentication
- CMAC address-based authentication is being used for the client through MAC Authentication
- DFortiGate is authenticating the client using 802.1X authentication.
How the community answered
(24 responses)- A4% (1)
- B4% (1)
- C79% (19)
- D13% (3)
Explanation
The RADIUS Access-Request shows the client's MAC address in the User-Name attribute, which is the standard behavior when MAC Authentication Bypass (MAB) is used. Since the client is a non-802.1X device, FortiSwitch falls back to MAB, using the MAC address as the user identifier for authentication against FortiAuthenticator.
Topics
Community Discussion
No community discussion yet for this question.

