QuestionQ6

Authentication

A network administrator is configuring a RADIUS server on FortiGate for remote-user authentication. The administrator configures FortiGate to forward authentication requests to FortiAuthenticator, which then proxies them to a Windows Active Directory (AD) server through LDAP.

What is the primary benefit of using FortiAuthenticator in this configuration?

  • A FortiAuthenticator encrypts the RADIUS authentication traffic between FortiGate and the AD server, securing communication.
  • B This configuration provides a solution to the CHAP-to-LDAP dilemma, enabling MSCHAPv2 authentication.
  • C FortiAuthenticator simplifies the configuration by allowing FortiGate to use LDAP directly for authentication without the need for RADIUS.
  • D The configuration allows FortiGate to directly authenticate remote users against Windows Active Directory without the need for an intermediate proxy.
Explanation

FortiAuthenticator bridges the protocol mismatch between RADIUS challenge-response authentication and LDAP-based Active Directory authentication. This addresses the CHAP-to-LDAP dilemma and enables MSCHAPv2 authentication.

Community Discussion

No comments yet. Be the first to start the discussion!