nerdexam
Fortinet

FCSS_EFW_AD-7.4 · Question #23

A company's guest internet policy, operating in proxy mode, blocks access to Artificial Intelligence Technology sites using FortiGuard. However, a guest user accessed a page in this category using…

The correct answer is B. In the Protocol Port Mapping section of the SSL/SSH Inspection Profile, enter 443, 8443 to. When FortiGate is operating in proxy mode with full SSL inspection enabled, it inspects encrypted HTTPS traffic by default on port 443. However, some websites may use non-standard HTTPS ports (such as 8443), which FortiGate does not inspect unless explicitly configured. To…

Security Profiles

Question

A company's guest internet policy, operating in proxy mode, blocks access to Artificial Intelligence Technology sites using FortiGuard. However, a guest user accessed a page in this category using port 8443. Which configuration changes are required for FortiGate to analyze HTTPS traffic on nonstandard ports like 8443 when full SSL inspection is active in the guest policy?

Options

  • AAdd a URL wildcard domain to the website CA certificate and use it in the SSL/SSH Inspection
  • BIn the Protocol Port Mapping section of the SSL/SSH Inspection Profile, enter 443, 8443 to
  • CTo analyze nonstandard ports in web filter profiles, use TLSv1.3 in the SSL/SSH Inspection
  • DAdministrators can block traffic on nonstandard ports by enabling the SNI check in the

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    75% (18)
  • C
    4% (1)
  • D
    13% (3)

Explanation

When FortiGate is operating in proxy mode with full SSL inspection enabled, it inspects encrypted HTTPS traffic by default on port 443. However, some websites may use non-standard HTTPS ports (such as 8443), which FortiGate does not inspect unless explicitly configured. To ensure that FortiGate inspects HTTPS traffic on port 8443, administrators must manually add port 8443 in the Protocol Port Mapping section of the SSL/SSH Inspection Profile. This allows FortiGate to treat HTTPS traffic on port 8443 the same as traffic on port 443, enabling proper inspection and enforcement of FortiGuard category-based web filtering.

Topics

#SSL inspection#nonstandard ports#protocol port mapping#web filter

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.4 Practice