NSE4 · Question #493
Which are valid replies from a RADIUS server to an ACCESS-REQUEST packet from a FortiGate? (Choose two.)
The correct answer is A. ACCESS-CHALLENGE D. ACCESS-REJECT. A RADIUS server can respond to a FortiGate's ACCESS-REQUEST packet with either an ACCESS-CHALLENGE, requiring further information, or an ACCESS-REJECT, denying access.
Question
Which are valid replies from a RADIUS server to an ACCESS-REQUEST packet from a FortiGate? (Choose two.)
Options
- AACCESS-CHALLENGE
- BACCESS-RESTRICT
- CACCESS-PENDING
- DACCESS-REJECT
How the community answered
(32 responses)- A91% (29)
- B3% (1)
- C6% (2)
Why each option
A RADIUS server can respond to a FortiGate's ACCESS-REQUEST packet with either an ACCESS-CHALLENGE, requiring further information, or an ACCESS-REJECT, denying access.
An ACCESS-CHALLENGE packet is a standard RADIUS reply indicating that the authentication server needs additional information or a secondary response from the client before it can make a final access decision.
ACCESS-RESTRICT is not a standard RADIUS packet type for replies to an ACCESS-REQUEST.
ACCESS-PENDING is not a standard RADIUS packet type for replies to an ACCESS-REQUEST.
An ACCESS-REJECT packet is a standard RADIUS reply directly denying the authentication request, meaning the user's credentials were not accepted or authorization failed.
Concept tested: RADIUS authentication message types
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/684701/configuring-radius-server-for-authentication
Topics
Community Discussion
No community discussion yet for this question.