FCSS_EFW_AD-7.6 · Question #56
Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration. Why is FortiGate unable to detect HTTPS attacks on firewall policy ID…
The correct answer is C. The administrator must enable SSL inspection of the SSL server and upload the certificate of. The FortiGate SSL/SSH inspection profile is configured for Full SSL Inspection, which is necessary to analyze encrypted HTTPS traffic. However, the firewall policy is protecting an SSL server (the Linux server hosting the website), and currently, the SSL/SSH profile only…
Question
Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration. Why is FortiGate unable to detect HTTPS attacks on firewall policy ID 3 targeting the Linux server?
Exhibits
Options
- AThe administrator must set the policy to inspection mode to analyze the HTTPS packets as
- BThe administrator must enable HTTPS in the protocol port mapping of the deep- inspection
- CThe administrator must enable SSL inspection of the SSL server and upload the certificate of
- DThe administrator must enable cipher suites in the SSL/SSH inspection profile to decrypt the
How the community answered
(20 responses)- A15% (3)
- B25% (5)
- C55% (11)
- D5% (1)
Explanation
The FortiGate SSL/SSH inspection profile is configured for Full SSL Inspection, which is necessary to analyze encrypted HTTPS traffic. However, the firewall policy is protecting an SSL server (the Linux server hosting the website), and currently, the SSL/SSH profile only applies to client-side SSL inspection. To detect HTTPS-based attacks targeting the Linux server: FortiGate must act as an SSL intermediary to inspect encrypted traffic destined for the web server. The administrator must upload the SSL certificate of the Linux web server to FortiGate so that the server-side SSL inspection can decrypt incoming HTTPS traffic before analyzing it.
Topics
Community Discussion
No community discussion yet for this question.

