Courseiva

Configuring HTTPS and SSH Administrative Access from a Trusted Subnet

A network administrator needs to configure a FortiGate to allow HTTPS access to the GUI from the internal network. Which two steps must be performed?

⚠ Common exam trap

It's easy for candidates to think enabling HTTPS access on the interface alone is sufficient, forgetting that a firewall policy is also required to permit the traffic, or they mistakenly believe disabling HTTP is a prerequisite for HTTPS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a firewall policy that permits HTTPS traffic from internal to the FortiGate interface IP.

To allow HTTPS access to the GUI from the internal network, two actions are required. First, a firewall policy must be created to permit HTTPS traffic (TCP/443) from the internal network to the FortiGate's interface IP. This can be done via CLI with 'config firewall policy' or through the GUI. Second, HTTPS administrative access must be enabled on the internal interface. This is configured either via CLI with 'config system interface' and 'set allowaccess https' or by checking 'HTTPS' under Administrative Access in the GUI. Without both steps, GUI access will fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a firewall policy that permits HTTPS traffic from internal to the FortiGate interface IP.

    Why this is correct

    FortiGate evaluates interface-to-interface traffic against firewall policies, so a policy permitting HTTPS from the internal subnet to the FortiGate interface IP is required for GUI access. This satisfies the stem's constraint alongside enabling HTTPS administrative access.

  • ✓

    Enable HTTPS administrative access on the internal interface.

    Why this is correct

    Enabling HTTPS administrative access on the internal interface activates the management daemon's HTTPS listener bound to that interface, which is required before any policy can permit GUI traffic. This satisfies the stem's constraint of allowing HTTPS GUI access from the internal network.

  • ✗

    Disable HTTP administrative access on the internal interface.

    Why it's wrong here

    Disabling HTTP removes the plaintext web interface but does not enable the HTTPS service, so GUI access stays blocked. It is tempting because disabling insecure HTTP is a recognised hardening step, and would be correct alongside enabling HTTPS to prevent cleartext administrative logins.

  • ✗

    Enable SSH administrative access on the internal interface.

    Why it's wrong here

    SSH grants command-line access, not the web-based GUI, so enabling it on the internal interface leaves HTTPS administration unavailable. It is tempting because SSH is a standard FortiGate administrative protocol, and would be correct when the administrator needs secure CLI access to the internal interface.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator is configuring a new FortiGate and wants to allow management access from the internal network via HTTPS. The internal interface is port2 with IP 192.168.1.1/24. Which CLI command correctly enables HTTPS administrative access on port2?

medium
  • A.config firewall policy edit 1 set allowaccess https end
  • ✓ B.config system interface edit port2 set allowaccess https end
  • C.config system admin edit admin set https enable end
  • D.config system global set admin-https enable end

Why B: The `config system interface` command is the proper context to set the `allowaccess` parameter, which controls the administrative protocols (such as HTTPS) permitted on a specific FortiGate interface. By editing port2 and setting `allowaccess https`, the administrator enables HTTPS management access on that interface, allowing internal users to reach the FortiGate's web GUI via 192.168.1.1.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.