ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 3 - NSE7_LED-7.0 discussion

Report
Export

Refer to the exhibit.

Refer to the exhibit showing a network topology and SSID settings.

FortiGate is configured to use an external captive portal However wireless users are not able to see the captive portal login page

Which configuration change should the administrator make to fix the problem?

A.
Enable NAT in the firewall policy with the ID 13.
Answers
A.
Enable NAT in the firewall policy with the ID 13.
B.
Add the FortiAuthenticator and WindowsAD address objects as exempt destinations services
Answers
B.
Add the FortiAuthenticator and WindowsAD address objects as exempt destinations services
C.
Enable the captive-portal-exempt option in the firewall policy with the ID 12
Answers
C.
Enable the captive-portal-exempt option in the firewall policy with the ID 12
D.
Remove the guest.portal user group in the firewall policy with the ID 12
Answers
D.
Remove the guest.portal user group in the firewall policy with the ID 12
Suggested answer: B

Explanation:

According to the exhibit, the network topology and SSID settings show that FortiGate is configured to use an external captive portal hosted on FortiAuthenticator, which is connected to a Windows AD server for user authentication. However, wireless users are not able to see the captive portal login page, which means that they are not redirected to the external captive portal URL. Therefore, option B is true because adding the FortiAuthenticator and WindowsAD address objects as exempt destinations services will allow the wireless users to access the external captive portal URL without being blocked by the firewall policy. Option A is false because enabling NAT in the firewall policy with the ID 13 will not affect the redirection to the external captive portal URL, but rather the source IP address of the wireless traffic. Option C is false because enabling the captive-portal-exempt option in the firewall policy with the ID 12 will bypass the captive portal authentication for the wireless users, which is not the desired outcome. Option D is false because removing the guest.portal user group in the firewall policy with the ID 12 will prevent the wireless users from being authenticated by FortiGate, which is required for accessing the external captive portal.

asked 18/09/2024
john wick
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first