nerdexam
Juniper

JN0-635 · Question #73

You are using destination NAT to translate the address of your HTTPS server to a private address on your SRX Series device. You have decided to implement IDP SSL decryption. Upon enabling the…

The correct answer is D. Enable the IDPsensor-configurationdetector to detect address translation. See the full explanation below for the reasoning.

Question

You are using destination NAT to translate the address of your HTTPS server to a private address on your SRX Series device. You have decided to implement IDP SSL decryption. Upon enabling the decryption, you notice sessions are not decrypted. Which action resolves the problem?

Options

  • AReplace the server SSL certificate to use the public address.
  • BReboot the SRX Series device.
  • CIncrease the SSLsession-id-cache-timeoutvalue to any value greater than 5000 seconds.
  • DEnable the IDPsensor-configurationdetector to detect address translation.

How the community answered

(32 responses)
  • A
    16% (5)
  • B
    3% (1)
  • C
    6% (2)
  • D
    75% (24)

Community Discussion

No community discussion yet for this question.

Full JN0-635 Practice