NSE4 · Question #232
With FSSO, a domain user could authenticate either against the domain controller running the Collector Agent and Domain Controller Agent, or a domain controller running only the Domain Controller…
The correct answer is A. The login event is sent to the Collector Agent. C. The Collector Agent performs the DNS lookup for the authenticated client's IP address. When a user authenticates with a Secondary Domain Controller running only the FSSO Domain Controller Agent, the login event is sent to the Collector Agent, which then performs DNS lookup for the client's IP.
Question
With FSSO, a domain user could authenticate either against the domain controller running the Collector Agent and Domain Controller Agent, or a domain controller running only the Domain Controller Agent. If you attempt to authenticate with the Secondary Domain Controller running only the Domain Controller Agent, which of the following statements are correct? (Select all that apply.)
Options
- AThe login event is sent to the Collector Agent.
- BThe FortiGate unit receives the user information from the Domain Controller Agent of the
- CThe Collector Agent performs the DNS lookup for the authenticated client's IP address.
- DThe user cannot be authenticated with the FortiGate device in this manner because each Domain
How the community answered
(28 responses)- A82% (23)
- B7% (2)
- D11% (3)
Why each option
When a user authenticates with a Secondary Domain Controller running only the FSSO Domain Controller Agent, the login event is sent to the Collector Agent, which then performs DNS lookup for the client's IP.
The Domain Controller Agent's primary function is to detect user login events on the DC it's installed on and forward these events to the central FSSO Collector Agent.
The FortiGate unit communicates with the *Collector Agent* to retrieve user-to-IP mappings, not directly with individual Domain Controller Agents.
Upon receiving a login event (user and IP address) from a Domain Controller Agent, the FSSO Collector Agent typically performs a reverse DNS lookup for the authenticated client's IP address to retrieve its hostname, which is then used in user-IP mapping tables.
The FSSO architecture is designed for this scenario, allowing authentication through a Domain Controller Agent forwarding events to a central Collector Agent, making the statement incorrect.
Concept tested: FortiGate Single Sign-On (FSSO) architecture and flow
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/572175/fsso-architecture
Topics
Community Discussion
No community discussion yet for this question.