Question 1
Q1A hospital is deploying a secure wired network using FortiSwitch and FortiAuthenticator. The requirements are to authenticate medical devices using MAC Authentication Bypass (MAB) and doctors' laptops using 802.1X EAP-TLS. Both device types connect to the same switch ports. The network administrator has configured the port security mode to 802.1X-mac-based. However, only the 802.1X authentications are succeeding; the MAB devices fail to connect. What is a potential cause for this issue on the FortiSwitch port configuration?
Show answer & explanation
Correct answer: B
In 802.1X-mac-based security mode, both 802.1X and MAB can be used. However, MAB is not enabled by default. The administrator must explicitly enable it on the interface using the set mac-auth-bypass enable command. If this is not set, the switch will not attempt MAB for non-802.1X capable devices, causing their connections to fail.