Question 1
IntermediateWireless network security and access · Deploy VLANs and NAC for wireless segmentation
A hospital is deploying a Fortinet wireless network for both medical staff and patients. The security policy mandates that staff devices using 802.1X authentication are placed in VLAN 10, while patient guest devices using a FortiGate-hosted captive portal are placed in VLAN 20. Both SSIDs are broadcast from the same FortiAP-U series access points, and the policy also requires that all wireless client traffic be carried to the FortiGate over CAPWAP so that the FortiGate enforces the firewall policies for both groups. Which FortiAP SSID traffic mode meets these requirements?
Answer and explanation
Correct answer: B
In Tunnel mode, all wireless client traffic is encapsulated in CAPWAP and delivered to the FortiGate wireless controller, where each SSID (and its VLAN) terminates on a FortiGate interface. The FortiGate therefore enforces firewall policies and hosts the captive portal for both groups. In Bridge mode, traffic is placed directly onto the local LAN at the FortiAP and is not carried to the FortiGate over CAPWAP.
