FCSS_EFW_AD-7.6 · Question #30
Refer to the exhibit, which shows the packet capture output of a three-way handshake between FortiGate and FortiManager Cloud. What two conclusions can you draw from the exhibit? (Choose two.)
The correct answer is A. FortiGate will receive a certificate that supports multiple domains because FortiManager D. The wildcard for the domain *.fortinet-ca2.support.fortinet.com must be supported by. The packet capture output displays a TLS Client Hello message from FortiGate to FortiManager Cloud. This message contains Server Name Indication (SNI), which is used to indicate the domain name that FortiGate is trying to connect to. FortiGate will receive a certificate that…
Question
Refer to the exhibit, which shows the packet capture output of a three-way handshake between FortiGate and FortiManager Cloud. What two conclusions can you draw from the exhibit? (Choose two.)
Exhibit
Options
- AFortiGate will receive a certificate that supports multiple domains because FortiManager
- BFortiGate is connecting to the same IP server and will receive an independent certificate for its
- CIf the TLS handshake contains 17 cipher suites it means the TLS version must be 1.0 on this
- DThe wildcard for the domain *.fortinet-ca2.support.fortinet.com must be supported by
How the community answered
(27 responses)- A59% (16)
- B30% (8)
- C11% (3)
Explanation
The packet capture output displays a TLS Client Hello message from FortiGate to FortiManager Cloud. This message contains Server Name Indication (SNI), which is used to indicate the domain name that FortiGate is trying to connect to. FortiGate will receive a certificate that supports multiple domains because FortiManager operates in a cloud computing environment. FortiManager Cloud hosts multiple customers and domains under a shared infrastructure. The TLS handshake includes SNI (Server Name Indication), which allows FortiManager Cloud to serve multiple certificates based on the requested domain. This means FortiGate will likely receive a multi-domain or wildcard certificate that can be used for multiple customers under FortiManager Cloud. The wildcard for the domain .fortinet-ca2.support.fortinet.com must be supported by FortiManager The SNI extension contains the domain 9398.support.fortinet-ca2.fortinet.com. FortiManager Cloud must support wildcard certificates such as *.fortinet-ca2.support.fortinet.com to securely manage multiple subdomains and customers. This ensures that FortiGate can validate the server certificate without any TLS errors.
Topics
Community Discussion
No community discussion yet for this question.
