ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 17 - NSE8_812 discussion

Report
Export

Refer to the exhibits.

An administrator has configured a FortiGate and Forti Authenticator for two-factor authentication with FortiToken push notifications for their SSL VPN login. Upon initial review of the setup, the administrator has discovered that the customers can manually type in their two-factor code and authenticate but push notifications do not work Based on the information given in the exhibits, what must be done to fix this?

A.
On FG-1 port1, the ftm access protocol must be enabled.
Answers
A.
On FG-1 port1, the ftm access protocol must be enabled.
B.
FAC-1 must have an internet routable IP address for push notifications.
Answers
B.
FAC-1 must have an internet routable IP address for push notifications.
C.
On FG-1 CLI, the ftm-push server setting must point to 100.64.141.
Answers
C.
On FG-1 CLI, the ftm-push server setting must point to 100.64.141.
D.
On FAC-1, the FortiToken public IP setting must point to 100.64.1 41
Answers
D.
On FAC-1, the FortiToken public IP setting must point to 100.64.1 41
Suggested answer: C

Explanation:

The FortiGate and Forti Authenticator configuration shown in the exhibits is using two-factor authentication with FortiToken push notifications for SSL VPN login. FortiToken push notifications are a feature that allows users to receive a notification on their mobile devices when they attempt to log in to a FortiGate or FortiAuthenticator service, and approve or deny the login request with a single tap. However, push notifications do not work in this scenario, even though users can manually type in their two-factor code and authenticate. One possible reason for this issue is that the FortiGate does not know how to reach the FortiAuthenticator server for push notifications. Therefore, to fix this issue, one option is to configure the ftm-push server setting on FG-1 CLI, which specifies the IP address or FQDN of the FortiAuthenticator server that handles push notifications. In this case, since FAC-1 has an IP address of 100.64.141, the ftm-push server setting on FG-1 CLI must point to 100.64.141 as well. Reference:

https://docs.fortinet.com/document/fortiauthenticator/6.4.0/administrationguide/ 19662/fortitoken-mobile-push-notifications

asked 18/09/2024
Monique Canham
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first