(ISC)2
301B · Question #139
After upgrading LTM from v10 to v11, users are unable to connect to an application. The virtual server is using a client SSL profile for re-terminating SSL for payload inspection, but a server SSL pro
The correct answer is B. Change Secure Renegotiation to "Request.". See the full explanation below for the reasoning.
Question
After upgrading LTM from v10 to v11, users are unable to connect to an application. The virtual server is using a client SSL profile for re-terminating SSL for payload inspection, but a server SSL profile is being used to re-encrypt the request. A client side tcpdump did NOT show any differences between the traffic going directly to the server and the traffic being proxied by the LTM device. However, packet capture was done on the server, and differences were noted. Which modification will allow the LTM device to process the traffic correctly?
Options
- AEnable Strict Resume.
- BChange Secure Renegotiation to "Request."
- CEnable ProxySSL option in the server SSL profile.
- DChange to different ciphers on the server SSL profile.
How the community answered
(54 responses)- A11% (6)
- B83% (45)
- C4% (2)
- D2% (1)
Community Discussion
No community discussion yet for this question.