NSE4 Authentication and VPN Practice Question
A FortiGate admin configures a captive portal for guest users on a wireless network. Users can connect to the SSID but cannot access the internet. The admin verifies the firewall policy permits traffic from the captive portal interface to the internet. What is missing?
⚠ Common exam trap
Test-takers frequently assume captive portal is automatically enabled when a firewall policy allows traffic from the captive portal interface, but in FortiGate, the 'Enable Captive Portal' checkbox must be explicitly set on the policy to trigger the authentication redirect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall policy must have 'Enable Captive Portal' selected
For a captive portal to redirect unauthenticated users to the authentication page, the firewall policy that permits traffic from the captive portal interface to the internet must have the 'Enable Captive Portal' option selected. Without this setting, the FortiGate will not intercept HTTP/HTTPS requests and redirect them to the captive portal login page, so users remain unauthenticated and cannot access the internet even though the policy allows traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall policy must have 'Enable Captive Portal' selected
Why this is correct
The captive portal is a firewall-policy-level feature: on the FortiGate, you must enable 'Captive Portal' on the specific policy controlling the guest traffic (CLI: set captive-portal enable). This instructs the FortiGate to intercept HTTP/HTTPS sessions from unauthenticated clients and redirect them to the portal login page. Without this enablement, the portal page is never presented, and the guest traffic is simply blocked or forwarded according to the policy's normal settings.
- ✗
A DNS server must be configured on the FortiGate
Why it's wrong here
Configuring a DNS server on the FortiGate is not a captive-portal prerequisite; DNS is used for FortiGuard lookups, FQDN-based objects, and system-level resolution, none of which are required for the portal redirection mechanism. The portal intercepts traffic via the firewall policy and redirects to the FortiGate's own IP, independent of the FortiGate's DNS settings. Guest clients need DNS to browse the Internet, but they can use a DNS server learned from DHCP—so absence of FortiGate DNS does not prevent the portal page from loading.
- ✗
The users must be added to the local user database
Why it's wrong here
Pre-adding users to the local user database is not mandatory for a guest captive portal. The FortiGate can authenticate portal logins against local users, LDAP, or RADIUS, but typical guest access uses self-registration, a generic guest password, or a dynamically created account under Guest Management after the user submits the portal form. The portal only needs an authentication source or a guest policy; it does not require every guest to be pre-provisioned as a static local user object.
- ✗
The wireless controller must be configured with a RADIUS server
Why it's wrong here
Configuring a RADIUS server on the wireless controller is irrelevant to a guest captive portal because RADIUS is only needed for WPA2/802.1X enterprise authentication or centralized authentication decisions, not for the portal itself. The FortiGate delivers the login page through its firewall policy captive-portal setting, and the SSID's role is merely to carry the guest traffic to that policy. A guest SSID can be entirely open with a captive portal and have no RADIUS server configured anywhere in the path.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.