NSE4 Firewall Policies and NAT Practice Question
Which THREE conditions must be met for a firewall policy with FSSO authentication to work correctly?
⚠ Common exam trap
Many exam-takers confuse source and destination address fields in the policy, mistakenly thinking the user's IP must be in the destination range, or assume FSSO requires local FortiGate authentication, when in fact it relies on domain authentication and the collector agent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate must be able to communicate with the domain controller
FSSO (Fortinet Single Sign-On) relies on the FortiGate communicating with the domain controller to retrieve user login events via NetAPI or WMI. Without this communication, the FortiGate cannot map user identities to IP addresses, which is essential for FSSO-based authentication in firewall policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The FortiGate must be able to communicate with the domain controller
Why this is correct
FSSO relies on the FortiGate or Collector Agent receiving user login events from the domain controller. Without network connectivity to the DC, the FortiGate cannot learn which user logged in or which groups that user belongs to, so the policy cannot match the user. This communication is typically via LDAP or a proprietary FSSO polling/eventing protocol, and any firewall rule blocking it will break FSSO.
- ✗
The user's IP address must be in the destination address range of the policy
Why it's wrong here
The user's IP must match the SOURCE address of the policy, not the destination. In an FSSO policy, the firewall identifies the user by their source IP address, which is mapped to a logged-in user via the FSSO collector. The destination address defines the server or network being accessed, so the user's IP is never compared to the destination range.
- ✓
The user must be a member of a group that is referenced in the firewall policy
Why this is correct
The FSSO policy references a specific AD group, and the user's membership in that group is what authorizes traffic. When the DC reports a login event, it includes the user's group memberships, and FortiOS compares those to the group configured in the policy. If the user is not a member of any referenced group, no FSSO policy matches, and the traffic is dropped or evaluated against other policies.
- ✓
The FSSO collector agent must be running and properly configured
Why this is correct
The Collector Agent is the component that listens to domain controller security logs or polls for logon events and then pushes the IP-to-user mapping to the FortiGate. If it is not running or misconfigured, the FortiGate receives no login information, so user-based policies cannot be enforced. The agent must have the correct domain credentials and be able to reach both the DC and the FortiGate.
- ✗
The user must be authenticated to the FortiGate locally
Why it's wrong here
FSSO is explicitly designed to leverage Windows Active Directory authentication; the user's credentials are validated by the domain controller when they log in to the domain. The FortiGate does not perform local authentication or ask for a password; it simply trusts the mapping supplied by the FSSO collector. Local authentication would require a different user store and is not part of FSSO.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.