FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt. What is the most likely reason for this situation?
A.
The Service DNS is required in the firewall policy.
B.
The user is using an incorrect user name.
C.
The Remote-users group is not added to the Destination.
Just confirmed the answer is A by replicating this config on my Fortigate. If you don't add DNS to the policy you just get a timeout and the browser cannot find the site.
Once you add DNS you get a prompt that you must log in to access the internet.
I think the confusing part of this question is that it reads as if the user is able to access the internet and is not being prompted. When in fact, they are not getting prompted AND they can't access the internet.
A. The Service DNS is required in the firewall policy.
"DNS traffic can be allowed if user has not authenticated yet
Hostname resolution is often required by the application layer protocol (HTTP/HTTPS/FTP/Telnet) that is used to authenticate
DNS service must be explicity listed as a service in the policy"
Reference: FortiGate 7.4 Administration Study Guide, page 115 (Firewall Policy - Service)
If you selected B it says that you are only being advised that the username/password is incorrect and you can re-type the credentials but the login prompt would appear.
A firewall policy also checks the service in order to transport the named protocols or group of protocols. No service (with the exception of DNS) is allowed through the firewall policy before successful user authentication. DNS is usually used by HTTP so that people can use domain names for websites, instead of their IP address. DNS is allowed because it is a base protocol and will most likely be required to initially see proper authentication protocol traffic. Hostname resolution is almost always a requirement for any protocol. However, the DNS service must still be defined in the policy as allowed, in order for it to pass.
A is the correct answer
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
fa7474b
Highly Voted 2 months agoKunot
Most Recent 15 hours, 36 minutes agovuhidus
3 weeks, 4 days agos4mu3l007
1 month, 2 weeks agoherlock_sholmes_2810
2 months, 4 weeks agoKnocks
3 months agomiguelmagr
2 months, 2 weeks agoTIGERZ44
3 months, 1 week agowsdeffwd
3 months, 1 week agobob511
3 months, 2 weeks ago