LDAPS Certificate Requirement for FTD Remote Access VPN
A VPN administrator converted an instance of Cisco Secure Firewall Threat Defense, which is managed by Cisco Secure Firewall Management Center, from using LDAP to LDAPS for remote access VPN authentication. Which certificate must be added to allow for remote users to authenticate over the VPN?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The FTD device directly handles remote access VPN authentication, meaning it must establish the SSL connection to the LDAPS server and therefore trust its certificate.
When converting from LDAP to LDAPS for remote access VPN authentication on a Cisco Secure Firewall Threat Defense (FTD), the FTD must trust the LDAPS server. This page establishes that the LDAPS server certificate must be added to the FTD, not the FMC.
Choosing B because LDAPS realms are configured in FMC, but FMC does not perform the RA VPN authentication; the FTD does, so FTD requires the certificate trust.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
For remote access VPN authentication, the Cisco Secure Firewall Threat Defense (FTD) device acts as the AAA client and directly initiates the connection to the LDAPS server. To establish a secure SSL/TLS tunnel for LDAPS, the FTD must authenticate the LDAPS server, which requires the FTD to possess the LDAPS server's root CA certificate in its trust store. Therefore, the LDAPS server certificate must be added to the FTD (typically configured via FMC's Objects > PKI > Trusted CAs and deployed to the FTD).Why the Other Options Are Wrong
Option B is incorrect because while the FMC is used to configure the identity realm and PKI objects, the FMC itself does not perform the RA VPN authentication or initiate the LDAPS connection; the FTD does. Option A is incorrect because the LDAPS server does not need to trust the FTD's certificate for the FTD to authenticate to it over LDAPS. Option C is incorrect because the FMC is not the device establishing the LDAPS connection for VPN authentication.Community Comment Notes
Some learners incorrectly assume FMC handles the authentication because realms are configured there, as noted by jcjcjcjcjc who stated "If you use FMC you add it on the FMC". However, as whysohardwhy correctly pointed out, "FTD does the authN, not FMC". The certificate is configured in FMC but deployed to FTD, with artilling providing the exact path "under Objects > PKI > Trusted CAs > Add Trusted CA" to satisfy the FTD's trust requirement.Official Reference
Exam Strategy
Remember that FMC is only a management plane; the FTD is the data plane device that actually processes VPN connections and authentication. Therefore, trust relationships (like LDAPS certificates) must be established on the FTD.