QuestionQ5

Authentication

Refer to the following exhibits.

Question Image

Question Image

You are configuring FortiAuthenticator to authenticate wireless users through Active Directory via LDAP. The users send authentication requests to FortiAuthenticator through RADIUS, and FortiAuthenticator acts as the back-end authentication server.

On FortiGate, a RADIUS server that points to FortiAuthenticator is configured. Although FortiGate successfully connects to the RADIUS server, wireless-user authentication fails.

After reviewing the configurations on both FortiGate and FortiAuthenticator, you determine that the RADIUS Service Policy appears misconfigured.

Which configuration step might be missing?

  • A In the Authentication Factors section, select Password-only.
  • B In the Identity Sources section, enable Windows AD Domain Authentication.
  • C In the Identity Sources section, select a different Username format.
  • D In the Authentication Factors section, enable Adaptive Authentication.
Explanation

PEAP/EAP-MSCHAPv2 wireless authentication requires Windows AD domain authentication in the RADIUS policy’s Identity Sources. This makes FortiAuthenticator authenticate through NTLM after joining the AD domain, rather than using the default LDAP authentication process.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!