LDAPS Certificate Requirement for FTD Remote Access VPN

Answer Correct answer: D — The LDAPS server certificate must be added to Secure Firewall Threat Defense to establish trust for the SSL connection.

A VPN administrator converted an instance of Cisco Secure Firewall Threat Defense, which is managed by Cisco Secure Firewall Management Center, from using LDAP to LDAPS for remote access VPN authentication. Which certificate must be added to allow for remote users to authenticate over the VPN?

  1. Secure Firewall Threat Defense certificate must be added to the LDAPS server
  2. LDAPS server certificate must be added to Secure Firewall Management Center realms
  3. Secure Firewall Management Center certificate must be added to the LDAPS server
  4. LDAPS server certificate must be added to Secure Firewall Threat Defense Correct Answer

Community Votes

B
67%
D
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The FTD device directly handles remote access VPN authentication, meaning it must establish the SSL connection to the LDAPS server and therefore trust its certificate.

When converting from LDAP to LDAPS for remote access VPN authentication on a Cisco Secure Firewall Threat Defense (FTD), the FTD must trust the LDAPS server. This page establishes that the LDAPS server certificate must be added to the FTD, not the FMC.

Choosing B because LDAPS realms are configured in FMC, but FMC does not perform the RA VPN authentication; the FTD does, so FTD requires the certificate trust.

Community Discussion (4 comments)

jcjcjcjcjc 👍 1 Selected: B
If you use FMC you add it on the FMC
whysohardwhy 👍 1 Selected: D
FTD does the authN, not FMC
Pata311 👍 3 Selected: B
The certificate must be added to FMC realm
artilling 👍 1 Selected: D
Correct Answer: D import the Root CA Certificate that has signed the LDAPS service Certificate on the Windows Server under Objects > PKI > Trusted CAs > Add Trusted CA, as this is referenced under theDirectory Server Configuration of the Realm https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client-v4x/220880-configure-password-management-using-ldap.html#toc-hId--2065014694

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

For remote access VPN authentication, the Cisco Secure Firewall Threat Defense (FTD) device acts as the AAA client and directly initiates the connection to the LDAPS server. To establish a secure SSL/TLS tunnel for LDAPS, the FTD must authenticate the LDAPS server, which requires the FTD to possess the LDAPS server's root CA certificate in its trust store. Therefore, the LDAPS server certificate must be added to the FTD (typically configured via FMC's Objects > PKI > Trusted CAs and deployed to the FTD).

Why the Other Options Are Wrong

Option B is incorrect because while the FMC is used to configure the identity realm and PKI objects, the FMC itself does not perform the RA VPN authentication or initiate the LDAPS connection; the FTD does. Option A is incorrect because the LDAPS server does not need to trust the FTD's certificate for the FTD to authenticate to it over LDAPS. Option C is incorrect because the FMC is not the device establishing the LDAPS connection for VPN authentication.

Community Comment Notes

Some learners incorrectly assume FMC handles the authentication because realms are configured there, as noted by jcjcjcjcjc who stated "If you use FMC you add it on the FMC". However, as whysohardwhy correctly pointed out, "FTD does the authN, not FMC". The certificate is configured in FMC but deployed to FTD, with artilling providing the exact path "under Objects > PKI > Trusted CAs > Add Trusted CA" to satisfy the FTD's trust requirement.

Official Reference

Exam Strategy

Remember that FMC is only a management plane; the FTD is the data plane device that actually processes VPN connections and authentication. Therefore, trust relationships (like LDAPS certificates) must be established on the FTD.

Related Analysis

← Back to 300-710 Study Guide