300-710 · Question #425
Refer to the exhibit. A Cisco Secure Firewall Management Center, 7.0 device fails to receive intelligence feed updates. The Cisco Secure Firewall Management Center is configured to use a proxy…
The correct answer is D. Bypass the proxy server for intelligence.sourcefire.com. When a proxy server performs SSL inspection (man-in-the-middle decryption), it intercepts HTTPS connections and re-signs them with the proxy's own certificate. Cisco FMC validates the certificate chain when downloading intelligence feeds from intelligence.sourcefire.com; if the…
Question
Refer to the exhibit. A Cisco Secure Firewall Management Center, 7.0 device fails to receive intelligence feed updates. The Cisco Secure Firewall Management Center is configured to use a proxy server that performs SSL inspection. Which action allows the Cisco Secure Firewall Management Center device to download the intelligence feed updates?
Exhibit
Options
- AInstall a self-signed certificate on the proxy server for intelligence.sourcefire.com.
- BVerify that the proxy server can use HTTPS to communicate to the internet.
- CEnsure that proxy authentication is disabled for the Cisco Secure Firewall Management
- DBypass the proxy server for intelligence.sourcefire.com.
How the community answered
(17 responses)- A18% (3)
- B6% (1)
- C6% (1)
- D71% (12)
Explanation
When a proxy server performs SSL inspection (man-in-the-middle decryption), it intercepts HTTPS connections and re-signs them with the proxy's own certificate. Cisco FMC validates the certificate chain when downloading intelligence feeds from intelligence.sourcefire.com; if the proxy substitutes its own certificate, the certificate validation fails and the download is blocked. The cleanest solution is to configure the proxy to bypass SSL inspection for intelligence.sourcefire.com, allowing FMC to receive the authentic certificate from Sourcefire's servers and complete the TLS handshake successfully. Installing a self-signed cert on the proxy (Option A) does not resolve the trust issue unless that cert is also trusted by FMC.
Topics
Community Discussion
No community discussion yet for this question.
