nerdexam
Fortinet

FCSS_LED_AR-7.6 · Question #42

Refer to the exhibits. Examine the firewall policy configuration and SSID settings. Users trying to connect to the new Guest wireless network should be redirected to an external captive portal…

The correct answer is C. A firewall policy with the ID 11 is missing to enable the captive-portal-exempt option. The pre-auth traffic to the external portal is not allowed. The policy from the guest SSID to the portal/AD must be marked as captive-portal-exempt so unauthenticated clients can reach the portal/DNS to load the login page.

Troubleshooting and Best Practices

Question

Refer to the exhibits. Examine the firewall policy configuration and SSID settings. Users trying to connect to the new Guest wireless network should be redirected to an external captive portal, however, these wireless users are not able to see the captive portal login page. The external captive portal URL has been verified as correct, yet the issue persists. Which configuration change should fix the problem?

Exhibits

FCSS_LED_AR-7.6 question #42 exhibit 1
FCSS_LED_AR-7.6 question #42 exhibit 2

Options

  • AAdd FortiAuthenticator and WindowsAD as exempt sources.
  • BSecurity mode should be set to WPA2 Enterprise to authenticate through RADIUS.
  • CA firewall policy with the ID 11 is missing to enable the captive-portal-exempt option.
  • DInclude the user group guest.portal in the firewall policy.

How the community answered

(17 responses)
  • A
    24% (4)
  • B
    6% (1)
  • C
    59% (10)
  • D
    12% (2)

Explanation

The pre-auth traffic to the external portal is not allowed. The policy from the guest SSID to the portal/AD must be marked as captive-portal-exempt so unauthenticated clients can reach the portal/DNS to load the login page.

Topics

#captive portal#firewall policy#captive-portal-exempt#guest wireless

Community Discussion

No community discussion yet for this question.

Full FCSS_LED_AR-7.6 Practice