nerdexam
Fortinet

FCSS_LED_AR-7.6 · Question #38

You need to deploy a security policy on a FortiSwitch port connected to legacy printers that do not support 802.1X authentication. How can you configure the network to ensure these printers have…

The correct answer is A. Enable MAC Authentication Bypass (MAB) on the FortiSwitch port. When connecting non-802.1X-capable devices (like legacy printers, IP phones, or IoT devices) to a FortiSwitch managed by a FortiGate or FortiAuthenticator, you can still maintain network security by using MAC Authentication Bypass (MAB).

FortiSwitch Deployment and Configuration

Question

You need to deploy a security policy on a FortiSwitch port connected to legacy printers that do not support 802.1X authentication. How can you configure the network to ensure these printers have access while maintaining security?

Options

  • AEnable MAC Authentication Bypass (MAB) on the FortiSwitch port.
  • BConfigure the FortiSwitch port to operate in promiscuous mode.
  • CAssign the printers to a high-priority VLAN that bypasses security policies.
  • DUse port mirroring to copy traffic from the printer to another secured port for authentication.

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    3% (1)
  • D
    7% (2)

Explanation

When connecting non-802.1X-capable devices (like legacy printers, IP phones, or IoT devices) to a FortiSwitch managed by a FortiGate or FortiAuthenticator, you can still maintain network security by using MAC Authentication Bypass (MAB).

Topics

#MAC Authentication Bypass#802.1X bypass#legacy devices#FortiSwitch port security

Community Discussion

No community discussion yet for this question.

Full FCSS_LED_AR-7.6 Practice