NSE4 · Question #536
How do you configure inline SSL inspection on a firewall policy? (Choose two.)
The correct answer is A. Enable one or more flow-based security profiles on the firewall policy. B. Enable the SSL/SSH Inspection profile on the firewall policy.. To configure inline SSL inspection on a FortiGate firewall policy, you must enable an SSL/SSH Inspection profile and then apply one or more flow-based security profiles.
Question
How do you configure inline SSL inspection on a firewall policy? (Choose two.)
Options
- AEnable one or more flow-based security profiles on the firewall policy.
- BEnable the SSL/SSH Inspection profile on the firewall policy.
- CExecute the inline ssl inspection CLI command.
- DEnable one or more proxy-based security profiles on the firewall policy.
How the community answered
(29 responses)- A97% (28)
- C3% (1)
Why each option
To configure inline SSL inspection on a FortiGate firewall policy, you must enable an SSL/SSH Inspection profile and then apply one or more flow-based security profiles.
Inline SSL inspection works with flow-based inspection mode; once an SSL/SSH Inspection profile is enabled, applying flow-based security profiles allows these engines to inspect the decrypted traffic.
The SSL/SSH Inspection profile is the foundational component that enables the FortiGate to decrypt and re-encrypt SSL/TLS traffic, making it inspectable by other security profiles.
There is no single `inline ssl inspection CLI command` that enables and configures the feature on a policy; it is a combination of profile application within the firewall policy configuration.
Inline SSL inspection is inherently designed to work with *flow-based* inspection, not proxy-based inspection, which operates differently and typically involves a full proxy for Layer 7 analysis.
Concept tested: FortiGate inline SSL inspection configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526725/ssl-ssh-inspection
Topics
Community Discussion
No community discussion yet for this question.