Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE7_SSE_AD-25 Exam - Topic 4 Question 5 Discussion

A customer configured the On/off-net detection rule to disable FortiSASE VPN auto-connect when users are inside the corporate network. The rule is set to Connects with a known public IP using the company's public IP address. However, when the users are on the corporate network, the FortiSASE VPN still auto-connects. The customer has confirmed that traffic is going to the internet with the correct IP address.Which configuration is causing the issue? (Choose one answer)
C) Exempt endpoint from FortiSASE auto-connect is disabled when it should be enabled.
A) The On-net rule set configuration is incorrect.
B) Allow local LAN access when endpoint is on-net is disabled when it should be enabled.
D) Is connected to a known DNS server should be enabled and configured.

Fortinet NSE7_SSE_AD-25 Exam - Topic 4 Question 5 Discussion

Actual exam question for Fortinet's NSE7_SSE_AD-25 exam
Question #: 5
Topic #: 4
[All NSE7_SSE_AD-25 Questions]

A customer configured the On/off-net detection rule to disable FortiSASE VPN auto-connect when users are inside the corporate network. The rule is set to Connects with a known public IP using the company's public IP address. However, when the users are on the corporate network, the FortiSASE VPN still auto-connects. The customer has confirmed that traffic is going to the internet with the correct IP address.

Which configuration is causing the issue? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: C

The FortiSASE On/off-net detection feature is a two-part configuration designed to optimize bandwidth and user experience by determining when a device is in a trusted environment.

Rule Set Definition: The first part involves defining what constitutes an 'on-net' or 'on-fabric' status. In this scenario, the customer successfully configured a rule set named CERT-PUBLIC-IP using the Connects with a known public IP detection type. This tells FortiSASE that if the endpoint's public WAN IP matches the corporate gateway, it is considered to be on the corporate network.

Profile Exemption Logic: Defining the rule set is not enough to stop the VPN connection. Within the Endpoint Profile (under the Connection tab > On/off-net Settings), there is a specific toggle labeled Exempt endpoint from FortiSASE auto-connect when endpoint is on-net (or in some versions, Bypass FortiSASE when endpoint is on-net).

Exhibit Analysis: Looking at the provided exhibit (image_57097d.jpg), the 'Exempt endpoint from FortiSASE auto-connect...' toggle is clearly disabled (switched to the left).

Root Cause: Because this toggle is disabled, FortiClient identifies that it is 'on-net' based on the IP rule, but it has no instruction to skip the VPN connection. Consequently, the 'Automatically' initiate tunnel setting remains the dominant instruction, causing the VPN to connect regardless of the network location.

To resolve the issue, the administrator must enable the Exempt endpoint from FortiSASE auto-connect when endpoint is on-net option in the SASECert01 profile.


Contribute your Thoughts:

0/2000 characters
Sabrina
3 hours ago
I agree, but what about A? The On-net rule might be wrong.
upvoted 0 times
...
Winfred
5 days ago
I think it's B. Local LAN access should be enabled.
upvoted 0 times
...
Serina
10 days ago
Definitely not D, DNS shouldn't affect this.
upvoted 0 times
...
Brett
16 days ago
B could be the issue too, local LAN access is crucial.
upvoted 0 times
...
Dorcas
2 months ago
Wait, how can it still connect if the IP is correct?
upvoted 0 times
...
Hobert
2 months ago
I agree, A seems like the right choice here.
upvoted 0 times
...
Bulah
2 months ago
Sounds like the On-net rule might be off.
upvoted 0 times
...
Janine
3 months ago
I think C could also be a factor, just saying!
upvoted 0 times
...
Camellia
3 months ago
Definitely check if local LAN access is enabled.
upvoted 0 times
...
Owen
3 months ago
Wait, are we sure the DNS server setting is even relevant here?
upvoted 0 times
...
Gabriele
3 months ago
I agree, A seems like the right choice.
upvoted 0 times
...
Lynna
3 months ago
Sounds like the On-net rule might be off.
upvoted 0 times
...
Paris
3 months ago
I vaguely remember that DNS settings can affect VPN behavior, so maybe option D is worth considering too.
upvoted 0 times
...
Chauncey
4 months ago
I feel like option A could also be a possibility since the on-net rule might not be set up correctly, but I can't recall the specifics.
upvoted 0 times
...
Emiko
4 months ago
I think it might be option B because allowing local LAN access seems crucial for preventing the VPN from connecting when on the corporate network.
upvoted 0 times
...
Sage
4 months ago
I remember practicing a similar question about on-net rules, but I'm not entirely sure which option is correct here.
upvoted 0 times
...

Save Cancel