Fortinet NSE6_FWF-6.4 Exam (page: 2)
Fortinet NSE 6 - Secure Wireless LAN 6.4
Updated on: 12-Feb-2026

Viewing Page 2 of 7

When configuring a wireless network for dynamic VLAN allocation, which three IETF attributes must be supplied by the radius server? (Choose three.)

  1. 81 Tunnel-Private-Group-ID
  2. 65 Tunnel-Medium-Type
  3. 83 Tunnel-Preference
  4. 58 Egress-VLAN-Name
  5. 64 Tunnel-Type

Answer(s): A,B,E

Explanation:

The RADIUS user attributes used for the VLAN ID assignment are:
-IETF 64 (Tunnel Type)—Set this to VLAN.
-IETF 65 (Tunnel Medium Type)—Set this to 802
-IETF 81 (Tunnel Private Group ID)—Set this to VLAN ID.


Reference:

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-vlan/71683-dynamicvlan-config.html



Which two phases are part of the process to plan a wireless design project? (Choose two.)

  1. Project information phase
  2. Hardware selection phase
  3. Site survey phase
  4. Installation phase

Answer(s): C,D


Reference:

https://www.sciencedirect.com/topics/computer-science/wireless-site-survey
https://www.automation.com/en-us/articles/2015-2/wireless-device-network-planning-and-design



When enabling security fabric on the FortiGate interface to manage FortiAPs, which two types of communication channels are established between FortiGate and FortiAPs? (Choose two.)

  1. Control channels
  2. Security channels
  3. FortLink channels
  4. Data channels

Answer(s): A,D

Explanation:

The control channel for managing traffic, which is always encrypted by DTLS. l The data channel for carrying client data packets.


Reference:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/ac61f4d3-ce67-11e9-8977-00505692583a/FortiWiFi_and_FortiAP-6.2-Cookbook.pdf



Part of the location service registration process is to link FortiAPs in FortiPresence.

Which two management services can configure the discovered AP registration information from the FortiPresence cloud? (Choose two.)

  1. AP Manager
  2. FortiAP Cloud
  3. FortiSwitch
  4. FortiGate

Answer(s): B,D

Explanation:

FortiGate, FortiCloud wireless access points (send visitor data in the form of station reports directly to FortiPresence)


Reference:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/df877622-c976-11e9-8977-00505692583a/FortiPresence-v4.3-release-notes.pdf



Which two configurations are compatible for Wireless Single Sign-On (WSSO)? (Choose two.)

  1. A VAP configured for captive portal authentication
  2. A VAP configured for WPA2 or 3 Enterprise
  3. A VAP configured to authenticate locally on FortiGate
  4. A VAP configured to authenticate using a radius server

Answer(s): B,D

Explanation:

In the SSID choose WPA2-Enterprise authentication.
WSSO is RADIUS-based authentication that passes the user's user group memberships to the FortiGate.


Reference:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/b92a67f9-73a6-11ea-9384-00505692583a/FortiWiFi_and_FortiAP-6.4.2-Configuration_Guide.pdf



Viewing Page 2 of 7



Share your comments for Fortinet NSE6_FWF-6.4 exam with other users:

Abhi 9/19/2023 1:22:00 PM

thanks for helping us
Anonymous