NSE4 Authentication and VPN Practice Question
An administrator needs to implement two-factor authentication for SSL VPN access using FortiToken. Which configuration steps are required?
⚠ Common exam trap
Test-takers frequently assume two-factor authentication can be enabled globally on the SSL VPN portal or firewall policy, but Fortinet specifically requires the token to be assigned to the individual user object with the authentication method set to two-factor, making option A the only correct step among the choices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign a FortiToken to the user and set the user's authentication method to two-factor
To implement two-factor authentication for SSL VPN using FortiToken, you must assign a FortiToken to the user and set the user's authentication method to two-factor. This is done in the user configuration (e.g., under User & Authentication > User Definition) by selecting 'FortiToken' as the second factor and linking the token serial number. This ensures that during SSL VPN login, the user must provide both their password and a one-time password from the FortiToken, which is validated locally by the FortiGate without requiring an external RADIUS server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign a FortiToken to the user and set the user's authentication method to two-factor
Why this is correct
In FortiOS, two-factor authentication is a property of the user object, not the service. You must first assign a FortiToken (hardware or mobile token) to the user, then set the user's 'Two-factor Authentication' to 'FortiToken' (or 'Email' etc). Only then will FortiGate challenge the user with a token code during any authentication flow, including firewall login, SSL VPN, or IPsec. This ensures the token is bound to the user and enforced universally.
- ✗
Configure the RADIUS server to send FortiToken challenges
Why it's wrong here
FortiToken is a FortiGate-managed token; RADIUS servers do not generate or send FortiToken challenges. When using RADIUS for authentication, the FortiGate can verify tokens locally if the user is a local user with a token; alternatively, RADIUS can return an Access-Challenge for other OTP mechanisms, but that is not FortiToken. FortiToken is validated by FortiGate or FortiToken Cloud, not by a RADIUS server. Trying to configure RADIUS to send FortiToken challenges would be ineffective because the RADIUS protocol has no such attribute.
- ✗
Enable FortiToken on the firewall policy
Why it's wrong here
Firewall policies in FortiOS are traffic-matching rules that reference address, user, and service objects; they do not contain a FortiToken setting. User authentication enforcement on a policy is done by selecting an identity-based policy that triggers authentication for the matched source user(s), but the method of two-factor is inherited from the user object. There is no checkbox or field on a firewall policy to enable FortiToken; token authentication is always a user-level attribute.
- ✗
Enable two-factor authentication on the SSL VPN portal settings
Why it's wrong here
SSL VPN portal settings control the web portal's appearance and options (like tunnel mode, bookmark list, and host check), but they do not provide a separate two-factor toggle. Authentication is performed by the VPN realm and the user group, which reference user objects; the portal is only shown after successful authentication. Setting two-factor on the portal would be nonexistent; the correct scope is the user object, as that is where the FortiToken is bound and enforced.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.