New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_FNC_AD_7.6 Exam - Topic 4 Question 3 Discussion

Actual exam question for Fortinet's NSE5_FNC_AD_7.6 exam
Question #: 3
Topic #: 4
[All NSE5_FNC_AD_7.6 Questions]

An administrator wants FortiNAC-F to return a group of user-defined RADIUS attributes in RADIUS responses.

Which condition must be true to achieve this?

Show Suggested Answer Hide Answer
Suggested Answer: B

In FortiNAC-F, the RADIUS Attribute Groups feature allows administrators to return customized RADIUS attributes (such as specific VLAN IDs, filter IDs, or vendor-specific attributes) in an Access-Accept packet sent back to a network device. This is particularly useful for supporting 'Generic RADIUS' devices that are not natively supported but can be managed using standard AVPairs.

According to the FortiNAC-F Generic RADIUS Wired Cookbook and the RADIUS Attribute Groups section of the Administration Guide, there is one critical prerequisite for this feature to function: the inbound RADIUS request must contain the Calling-Station-ID attribute. The Calling-Station-ID typically contains the MAC address of the connecting endpoint. Because FortiNAC-F is a host-centric system, it uses the MAC address as the unique identifier to look up the host record, evaluate the associated Network Access Policy, and determine which Logical Network (and thus which Attribute Group) should be applied. If the incoming request lacks this attribute, FortiNAC-F cannot reliably identify the host and, as a safety mechanism, will not include any user-defined RADIUS attributes in the response. This ensures that unauthorized or unidentifiable devices do not receive privileged access through misapplied attributes.

'Configure a set of attributes that must be included in the RADIUS Access-Accept packet returned by FortiNAC... Requirement: Inbound RADIUS request must contain Calling-Station-Id. Otherwise, FortiNAC will not include the RADIUS attributes. This attribute is used to identify the host and its current state within the FortiNAC database.' --- FortiNAC-F 7.6.0 Generic RADIUS Wired Cookbook: Configure RADIUS Attribute Groups.


Contribute your Thoughts:

0/2000 characters
Valentin
5 days ago
I remember practicing a question about RADIUS attributes, and I feel like the Calling-Station-ID attribute is important, so maybe B is the right choice.
upvoted 0 times
...
Jolanda
10 days ago
I think the answer might be A, but I'm not completely sure if all devices need to support RFC 5176 for the attributes to be returned.
upvoted 0 times
...
Susy
15 days ago
Hmm, I'm a bit unsure about this one. I'll need to think through the RADIUS requirements and the FortiNAC-F functionality to determine the correct answer.
upvoted 0 times
...
Starr
20 days ago
Ah, a RADIUS-related question. I feel pretty confident about this one. Let me review the options and see which one best describes the condition for returning user-defined RADIUS attributes.
upvoted 0 times
...
Joesph
25 days ago
Alright, time to put on my problem-solving hat. This looks like it's testing my knowledge of RADIUS and FortiNAC-F configuration. I'll need to think through the details carefully.
upvoted 0 times
...
Melda
1 month ago
Okay, let me see here. I think the key is understanding what conditions are necessary for FortiNAC-F to return those attributes. I'll need to analyze each option closely.
upvoted 0 times
...
Maile
1 month ago
Hmm, this one seems a bit tricky. I'll need to carefully read through the options and think about the requirements for returning user-defined RADIUS attributes.
upvoted 0 times
...

Save Cancel