FCSS_LED_AR-7.6 · Question #32
A network administrator is configuring a RADIUS server on FortiGate to authenticate remote users. The administrator configures FortiGate to forward authentication requests to FortiAuthenticator…
The correct answer is B. This configuration provides a solution to the CHAP-to-LDAP dilemma, enabling MSCHAPv2. The primary benefit of using FortiAuthenticator as a RADIUS proxy is that it resolves the CHAP- to-LDAP dilemma. LDAP alone cannot support MSCHAPv2 authentication because it does not store user passwords in reversible form. FortiAuthenticator bridges this gap by handling…
Question
A network administrator is configuring a RADIUS server on FortiGate to authenticate remote users. The administrator configures FortiGate to forward authentication requests to FortiAuthenticator, which then proxies these requests to a Windows Active Directory (AD) server using LDAP. Which is the primary benefit of using FortiAuthenticator in this configuration?
Options
- AFortiAuthenticator encrypts the RADIUS authentication traffic between FortiGate and the AD
- BThis configuration provides a solution to the CHAP-to-LDAP dilemma, enabling MSCHAPv2
- CFortiAuthenticator simplifies the configuration by allowing FortiGate to use LDAP directly for
- DThe configuration allows FortiGate to directly authenticate remote users against Windows Active
How the community answered
(39 responses)- A3% (1)
- B82% (32)
- C10% (4)
- D5% (2)
Explanation
The primary benefit of using FortiAuthenticator as a RADIUS proxy is that it resolves the CHAP- to-LDAP dilemma. LDAP alone cannot support MSCHAPv2 authentication because it does not store user passwords in reversible form. FortiAuthenticator bridges this gap by handling MSCHAPv2 challenges with AD through LDAP, allowing secure remote user authentication.
Topics
Community Discussion
No community discussion yet for this question.