A network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication. The Cisco FMC can connect to the LDAPS server, but the Cisco FTD is not connecting. Which configuration must be enabled on the Cisco FTD?
A.
The LDAPS must be allowed through the access control policy.
B.
The RADIUS server must be defined.
C.
SSL must be set to a use TLSv1.2 or lower.
D.
DNS servers must be defined for name resolution.
D- https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215538-configure-firepower-management-center-an.html
see: 3. SSL or TLS does not work as expected
If you don't enable DNS on the FTDs, you can see errors in the pigtail log that suggest that LDAP is unreachable:
A DNS record for the AD server is required because LDAPS clients typically use DNS to locate the domain controller hosting the AD server. The DNS record for the AD server helps clients resolve the server's hostname to its IP address.
The correct answer is A. The LDAPS protocol is used for secure communication with an LDAP directory using SSL/TLS encryption. When the network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication, the LDAPS protocol must be allowed through the access control policy. This means that the firewall rule on the Cisco FTD must allow traffic on the LDAPS port (usually 636/tcp) from the VPN clients to the LDAPS server.
Option D (DNS servers must be defined for name resolution) is not correct because although DNS is important for name resolution, it is not directly related to LDAPS authentication.
I would vote D according to this thread:
https://community.cisco.com/t5/network-access-control/cisco-ftd-ldaps/td-p/4541263
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.300-710 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
THEODORABLE
1 year, 5 months agoInitial14
1 year, 6 months agoJoe_Blue
1 year, 7 months agogwb
7 months, 3 weeks agoJoe_Blue
1 year, 8 months agofreho
1 year, 8 months agoBaumb
1 year, 8 months ago