ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 1 - NSE7_LED-7.0 discussion

Report
Export

Refer to the exhibit

Examine the FortiGate RSSO configuration shown in the exhibit

FortiGate is configured to receive RADIUS accounting messages on port3 to authenticate RSSO users The users are located behind port3 and the internet link is connected to port1 FortiGate is processing incoming RADIUS accounting messages successfully and RSSO users are getting associated with the RSSO Group user group However all the users are able to access the internet, and the administrator wants to restrict internet access to RSSO users only

Which configuration change should the administrator make to fix the problem?

A.
Change the RADIUS Attribute Value selling to match the name of the RADIUS attribute containing the group membership information of the RSSO users
Answers
A.
Change the RADIUS Attribute Value selling to match the name of the RADIUS attribute containing the group membership information of the RSSO users
B.
Add RSSO Group to the firewall policy
Answers
B.
Add RSSO Group to the firewall policy
C.
Enable Security Fabric Connection on port3
Answers
C.
Enable Security Fabric Connection on port3
D.
Create a second firewall policy from port3 lo port1 and select the target destination subnets
Answers
D.
Create a second firewall policy from port3 lo port1 and select the target destination subnets
Suggested answer: B

Explanation:

According to the exhibit, the firewall policy from port3 to port1 has no user group specified, which means that it allows all users to access the internet. Therefore, option B is true because adding RSSO Group to the firewall policy will restrict internet access to RSSO users only. Option A is false because changing the RADIUS Attribute Value setting will not affect the firewall policy, but rather the RSSO user group membership. Option C is false because enabling Security Fabric Connection on port3 will not affect the firewall policy, but rather the communication between FortiGate and other Security Fabric devices. Option D is false because creating a second firewall policy from port3 to port1 will not affect the existing firewall policy, but rather create a redundant or conflicting policy.

asked 18/09/2024
SAM E REYES
34 questions
NextNext
User
Your answer:
0 comments
Sorted by

Leave a comment first