nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #55

Refer to the exhibit showing a debug output. An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate from where the collector agent is deployed is…

The correct answer is D. The FortiGate and the collector agent are using different TCP ports. The log shows FortiGate attempting to connect to 127.0.0.1:8000 and immediately getting "Connection refused," which means no process is listening on that port. In DC Agent mode both sides must match on the same TCP port (default 8000), so a port mismatch will cause exactly this

Troubleshooting Methodology and Tools

Question

Refer to the exhibit showing a debug output. An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate from where the collector agent is deployed is successful. The administrator then produces the debug output shown in the exhibit. What could be causing this error message?

Exhibit

FCSS_NST_SE-7.4 question #55 exhibit

Options

  • AThe TCP port 445 is blocked between FortiGate and collector agent.
  • BThe collector agent preshared password is mismatched.
  • CThe FortiGate cannot resolve the active directory server name.
  • DThe FortiGate and the collector agent are using different TCP ports.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    11% (3)
  • D
    79% (22)

Explanation

The log shows FortiGate attempting to connect to 127.0.0.1:8000 and immediately getting "Connection refused," which means no process is listening on that port. In DC Agent mode both sides must match on the same TCP port (default 8000), so a port mismatch will cause exactly this

Topics

#FSSO#DC Agent Mode#collector agent#TCP port mismatch

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice