nerdexam
Fortinet

NSE8_812 · Question #89

Refer to the exhibit. The exhibit shows a topology where a FortiGate is split into two VDOMs, root and vd-lan. The root VDOM provides external SSL-VPN access, where the users are authenticated by a…

The correct answer is B. root is configured for FSSO while vd-lan is configured for RSSO. Correct answers are B and D.

Advanced VPN (IPsec, SSL, DMVPN)

Question

Refer to the exhibit. The exhibit shows a topology where a FortiGate is split into two VDOMs, root and vd-lan. The root VDOM provides external SSL-VPN access, where the users are authenticated by a FortiAuthenticator. The vd-lan VDOM provides internal access to a Web server. For the remote users to access the internal Web server, there are a few requirements as follows: - All traffic must come from the SSL-VPN. - The vd-lan VDOM only allows authenticated traffic to the Web server. - Users must only authenticate once, using the SSL-VPN portal. - SSL-VPN uses RADIUS-based authentication. Given these requirements and the topology shown in the exhibit, which two statements are true? (Choose two.)

Options

  • Avd-lan connects to FortiAuthenticator as a regular FSSO client.
  • Broot is configured for FSSO while vd-lan is configured for RSSO.
  • Croot sends "RADIUS Accounting Messages" to FortiAuthenticator
  • Dvd-lan receives authentication messages from root using FSSO.

How the community answered

(30 responses)
  • A
    17% (5)
  • B
    70% (21)
  • C
    7% (2)
  • D
    7% (2)

Explanation

Correct answers are B and D.

Topics

#VDOM#SSL-VPN#FSSO#RSSO

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice