100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

Fortinet NSE4 - Module 3 - Fortinet Single Sign-ON (FSSO)| QUESTIONS AND WELL VERIFIED ANSWERS |ACTUAL EXAM 100%

Rating
-
Sold
-
Pages
15
Grade
A+
Uploaded on
21-01-2025
Written in
2024/2025

Fortinet NSE4 - Module 3 - Fortinet Single Sign-ON (FSSO)| QUESTIONS AND WELL VERIFIED ANSWERS |ACTUAL EXAM 100%

Institution
Fortinet NSE
Course
Fortinet NSE









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Fortinet NSE
Course
Fortinet NSE

Document information

Uploaded on
January 21, 2025
Number of pages
15
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

Fortinet NSE4 - Module 3 - Fortinet Single Sign-ON
(FSSO)| QUESTIONS AND WELL VERIFIED ANSWERS
|ACTUAL EXAM 100%

DC Agent Mode
What is the commended mode for FSSO?

DC Agente Mode is the most scalable mode and is the recommended mode for FSSO.

DC Agent Mode
Dc agent mode requires:

One DC agent installed on each Windows DC


A collector agent which is another FSSO component.

DC Agent Mode
The collector agent is responsible for:

Group verification
Workstations checks
Updates of login records on FortiGate
Sending domain local security group, organizational units and global security group
information

DC Agent Mode
The agent DC is responsible for:

Monitoring user login events and forwarding them to the collector agents
Handling DNS lookups (by default).

, DC Agent Mode Process
There are 4 steps:

1. User authenticates against the Windows DC
2. DC agent sees the login event and forwards it to the collector agent
3. The collector agent receives the event and forwards it to FortiGate
4. FortiGate knows the user based on their IP, username, host name and user group.

DC Agent Mode Process
In what port is the communication between The Collector Agent and FortiGate ? What
is the listen port for updates from DC agents?! Both of this ports can be customized?!

TCP 8000
TCP 8002
Yes, both ports are customizable.

Collector Agent-Based Polling Mode
In the collector agent-based polling mode, the collector agent must be installed on a

Windows Server.
No FSSO DC agent is required.

Collector Agent-Based Polling Mode
Every few seconds, the collector agent polls each DC for user login events. The
collector agent uses (ports):

SMB (TCP 445) by default
TCP 135, 139 and UDP 137 as fallbacks.

Collector Agent-Based Polling Mode
TRUE or FAlSE - This mode requires a less complex installation, which reduces ongoing
maintenance.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
QUINTER New York College Of Dentistry
View profile
Follow You need to be logged in order to follow users or courses
Sold
339
Member since
2 year
Number of followers
104
Documents
38319
Last sold
1 week ago

3.4

57 reviews

5
25
4
8
3
7
2
1
1
16

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions