ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 28 - NSE7_LED-7.0 discussion

Report
Export

Refer to the exhibit.

Examine the RADIUS server configuration shown in the exhibit

An administrator has configured a RADIUS server on FortiGate that points to FortiAuthenticator FortiAuthenticator is acting as an authentication proxy and is configured to relay all authentication requests to a remote Windows AD server using LDAP

While testing the configuration the administrator noticed that the diagnose test authserver command worked with PAP, however authentication requests failed when using MSCHAP2

Which two solutions can the administrator implement to get MSCHAP2 authentication to work'' (Choose two.)

A.
On FortiAuthenticator enable Windows Active Directory Domain Authentication to add FortiAuthenticator to the Windows domain
Answers
A.
On FortiAuthenticator enable Windows Active Directory Domain Authentication to add FortiAuthenticator to the Windows domain
B.
On FortiGate configure the NAS IP setting on the RADIUS server
Answers
B.
On FortiGate configure the NAS IP setting on the RADIUS server
C.
On FortiAuthenticator change the back-end authentication server from LDAP to RADIUS
Answers
C.
On FortiAuthenticator change the back-end authentication server from LDAP to RADIUS
D.
On FortiGate update the Secret setting on the RADIUS server
Answers
D.
On FortiGate update the Secret setting on the RADIUS server
Suggested answer: A, C

Explanation:

According to the exhibit, the RADIUS server configuration on FortiGate points to FortiAuthenticator, which is acting as an authentication proxy and is configured to relay all authentication requests to a remote Windows AD server using LDAP. However, LDAP does not support MSCHAP2 authentication, which is required for RADIUS. Therefore, option A is true because on FortiAuthenticator, enabling Windows Active Directory Domain Authentication will add FortiAuthenticator to the Windows domain and allow it to use MSCHAP2 authentication with the AD server. Option C is also true because on FortiAuthenticator, changing the back-end authentication server from LDAP to RADIUS will allow it to use MSCHAP2 authentication with the AD server. Option B is false because on FortiGate, configuring the NAS IP setting on the RADIUS server will not affect the MSCHAP2 authentication, but rather the source IP address of the RADIUS packets. Option D is false because on FortiGate, updating the Secret setting on the RADIUS server will not affect the MSCHAP2 authentication, but rather the shared secret between FortiGate and FortiAuthenticator.

asked 18/09/2024
Nomandla Asiya
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first