nerdexam
Fortinet

FCSS_LED_AR-7.6 · Question #70

Refer to the exhibit. Review the exhibits to analyze the network topology, SSID settings, and firewall policies. FortiGate is configured to use an external captive portal for authentication to grant…

The correct answer is D. A firewall policy allowing Guest SSID traffic to reach FortiAuthenticator and Windows AD. From the exhibits: Security mode:Open Captive Portal: Enabled, portal typeAuthentication External External portal URL: https://fac.trainingad.training.lab/guest (FortiAuthenticator) Exempt destinations/services:FortiAuthenticator and WindowsAD From theGuest…

FortiAuthenticator Integration and Features

Question

Refer to the exhibit. Review the exhibits to analyze the network topology, SSID settings, and firewall policies. FortiGate is configured to use an external captive portal for authentication to grant access to a wireless network. During testing, it was found that users attempting to connect to the SSID cannot access the captive portal login page. What configuration change should be made to resolve this issue to allow users to access the captive portal?

Exhibits

FCSS_LED_AR-7.6 question #70 exhibit 1
FCSS_LED_AR-7.6 question #70 exhibit 2

Options

  • AChange the SSID security mode to WPA2-Enterprise for authentication.
  • BDisable HTTPS redirection for the captive portal authentication page.
  • CExclude FortiAuthenticator and Windows AD address objects from filtering.
  • DA firewall policy allowing Guest SSID traffic to reach FortiAuthenticator and Windows AD.

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    11% (5)
  • C
    2% (1)
  • D
    82% (37)

Explanation

From the exhibits: Security mode:Open Captive Portal: Enabled, portal typeAuthentication External External portal URL: https://fac.trainingad.training.lab/guest (FortiAuthenticator) Exempt destinations/services:FortiAuthenticator and WindowsAD From theGuest interface/zonetoport1 (Internet) Source user group:guest.portal(authenticated users) The flow for anexternal captive portalis: Client associates to theopen Guest SSID. Client makes an HTTP(S) request. FortiGate intercepts and redirects the client to theexternal portal. Client must be able toreach FortiAuthenticator's IP(and AD if the portal needs it)before Theexempt destinationsetting tells the captive portal logicnot to require authenticationfor traffic going to FortiAuthenticator and WindowsAD. However, there still must be a firewall policy that allows traffic from the Guest SSID subnet to those exempt destinations. The existing firewall policy uses theguest.portal user groupas a source condition, which only matchesaftersuccessful portal authentication. Before login, the client has no user identity, so: Traffic from the unauthenticated Guest client FortiAuthenticator isnot matchedby that policy. It hits theimplicit deny, so the browser never reaches the login page. To fix this, the administrator must: Create or modify a firewall policy thatallows traffic from the Guest SSID subnet/interface to FortiAuthenticator and WindowsAD without requiring user authentication. That is exactly what optionDdescribes.

Topics

#captive portal#external authentication#firewall policy#wireless SSID

Community Discussion

No community discussion yet for this question.

Full FCSS_LED_AR-7.6 Practice