ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 49 - NSE8_812 discussion

Report
Export

An administrator has configured a FortiGate device to authenticate SSL VPN users using digital certificates. A FortiAuthenticator is the certificate authority (CA) and the Online Certificate Status Protocol (OCSP) server.

Part of the FortiGate configuration is shown below:

Based on this configuration, which two statements are true? (Choose two.)

A.
OCSP checks will always go to the configured FortiAuthenticator
Answers
A.
OCSP checks will always go to the configured FortiAuthenticator
B.
The OCSP check of the certificate can be combined with a certificate revocation list.
Answers
B.
The OCSP check of the certificate can be combined with a certificate revocation list.
C.
OCSP certificate responses are never cached by the FortiGate.
Answers
C.
OCSP certificate responses are never cached by the FortiGate.
D.
If the OCSP server is unreachable, authentication will succeed if the certificate matches the CA.
Answers
D.
If the OCSP server is unreachable, authentication will succeed if the certificate matches the CA.
Suggested answer: A, D

Explanation:

A is correct because the OCSP server is configured as the FortiAuthenticator in the config vpn certificate ocsp-server section. D is correct because the config vpn ssl settings section has set ocspoption to allow. This means that if the OCSP server is unreachable, authentication will succeed if the certificate matches the CA. Reference:

https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/490351/ssl-vpnauthentication

https://docs.fortinet.com/document/fortigate/7.4.0/administrationguide/ 266506/ssl-vpn-with-certificate-authentication

asked 18/09/2024
Austine Ogheneruemu Onakpoma
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first