nerdexam
Fortinet

FCSS_LED_AR-7.6 · Question #63

Refer to the exhibits. A company has multiple FortiGate devices deployed and wants to centralize user authentication and authorization. The administrator decides to use FortiAuthenticator to convert…

The correct answer is A. The RADIUS Username and Client IPv4 attributes are not defined on FortiAuthenticator. In this design, FortiAuthenticator receivesRADIUS accounting (RSSO) messages, looks up the user in LDAP to get group information, theninjects FSSO logon eventstoward all FortiGate From the exhibits we know: FortiAuthenticatoris receiving RADIUS accountingfrom the RADIUS server…

FortiAuthenticator Integration and Features

Question

Refer to the exhibits. A company has multiple FortiGate devices deployed and wants to centralize user authentication and authorization. The administrator decides to use FortiAuthenticator to convert RSSO messages to FSSO, allowing all FortiGate devices to receive user authentication updates. After configuring FortiAuthenticator to receive RADIUS accounting messages, users can authenticate, but FortiGate does not enforce the correct policies based on user groups. Upon investigation, the administrator discovers that FortiAuthenticator is receiving RADIUS accounting messages from the RADIUS server and successfully queries LDAP for user group information. But, FSSO updates are not being sent to FortiGate devices and FortiGate firewall policies based on FSSO user groups are not being applied. What is the most likely reason FortiGate is not receiving FSSO updates?

Exhibits

FCSS_LED_AR-7.6 question #63 exhibit 1
FCSS_LED_AR-7.6 question #63 exhibit 2

Options

  • AThe RADIUS Username and Client IPv4 attributes are not defined on FortiAuthenticator.
  • BThe LDAP server is not configured to retrieve group memberships for RSSO users.
  • CFortiAuthenticator is missing the FSSO user group attribute in the configuration.
  • DThe FortiAuthenticator interface is not enabled to receive RADIUS accounting messages.

How the community answered

(58 responses)
  • A
    59% (34)
  • B
    24% (14)
  • C
    7% (4)
  • D
    10% (6)

Explanation

In this design, FortiAuthenticator receivesRADIUS accounting (RSSO) messages, looks up the user in LDAP to get group information, theninjects FSSO logon eventstoward all FortiGate From the exhibits we know: FortiAuthenticatoris receiving RADIUS accountingfrom the RADIUS server. LDAP queries are successful and return group membership. But FortiGatedoes not receive FSSO logons, so identity-based policies are not applied. For FortiAuthenticator to create an FSSO logon, the RADIUS accounting record must be correctlyparsed into at least: Client IP address These are mapped from the RADIUS attributes in theRADIUS Accounting SSO clientconfiguration (for example, User-Name and Framed-IP-Address). If these are not defined or mapped incorrectly, FortiAuthenticator can see the accounting packet butcannot build a valid FSSO session, so no update is sent to FortiGate. Thus the most likely root cause is: The RADIUS Username and Client IPv4 attributes are not correctly definedfor that RADIUS Accounting SSO client (option A).

Topics

#RSSO#FSSO#RADIUS accounting#user group enforcement

Community Discussion

No community discussion yet for this question.

Full FCSS_LED_AR-7.6 Practice