FCSS_LED_AR-7.6 · Question #9
Refer to the exhibits. A network administrator is configuring RADIUS single sign-on (RSSO) on FortiGate to dynamically assign users to specific user groups based on RADIUS accounting messages. Which…
The correct answer is B. Set the rsso-endpoint-attribute to define which RADIUS attribute will be used to extract username. C. Configure the sso-attribute in the RSSO agent settings to specify which RADIUS attribute. The rsso-endpoint-attribute must be configured to define which RADIUS attribute (e.g., User- Name) will be used to identify the user. The sso-attribute must be set in the RSSO agent settings to determine which RADIUS attribute (e.g., Class) will be used for dynamic user group…
Question
Refer to the exhibits. A network administrator is configuring RADIUS single sign-on (RSSO) on FortiGate to dynamically assign users to specific user groups based on RADIUS accounting messages. Which two configuration steps are required to ensure RSSO user group matching work correctly? (Choose two.)
Exhibits
Options
- AConfigure FortiGate to send RADIUS authentication requests instead of relying on accounting
- BSet the rsso-endpoint-attribute to define which RADIUS attribute will be used to extract username.
- CConfigure the sso-attribute in the RSSO agent settings to specify which RADIUS attribute
- DEnable the RSSO agent service on FortiGate to actively poll RADIUS servers for authentication
How the community answered
(27 responses)- A15% (4)
- B74% (20)
- D11% (3)
Explanation
The rsso-endpoint-attribute must be configured to define which RADIUS attribute (e.g., User- Name) will be used to identify the user. The sso-attribute must be set in the RSSO agent settings to determine which RADIUS attribute (e.g., Class) will be used for dynamic user group matching.
Topics
Community Discussion
No community discussion yet for this question.



