FCSS_LED_AR-7.6 · Question #40
Refer to the exhibits to analyze a network topology and SSID settings. FortiGate is configured to use an external captive portal for authentication to grant access to a wireless network. Testing…
The correct answer is C. Address objects FortiAuthenticator and WindowsAD must be included as exempt. With an external captive portal, clients must be allowed to reach the portal (and any required services like DNS/AD) before authentication. Add the portal servers (FortiAuthenticator and Windows AD) to the SSID's exempt destinations/services so unauthenticated users can be…
Question
Refer to the exhibits to analyze a network topology and SSID settings. FortiGate is configured to use an external captive portal for authentication to grant access to a wireless network. Testing detected that users attempting to access the SSID are not able to access the captive portal login page. Which configuration change should fix this issue?
Exhibits
Options
- AChange the SSID security mode to WPA2-Enterprise for authentication.
- BFirewall policy with the ID 13 must have NAT disabled.
- CAddress objects FortiAuthenticator and WindowsAD must be included as exempt
- DA firewall policy with port4 as source is missing.
How the community answered
(16 responses)- A6% (1)
- B19% (3)
- C69% (11)
- D6% (1)
Explanation
With an external captive portal, clients must be allowed to reach the portal (and any required services like DNS/AD) before authentication. Add the portal servers (FortiAuthenticator and Windows AD) to the SSID's exempt destinations/services so unauthenticated users can be redirected and load the login page.
Topics
Community Discussion
No community discussion yet for this question.


