NSE7_EFW-7.2 · Question #28
Refer to the exhibit, which shows an SSL certification inspection configuration. Which action does FortiGate take if the server name indication (SNI) does not match either the common name (CN) or…
The correct answer is B. FortiGate uses the CN information from the Subject field in the server certificate. If the domain in the SNI field does not match any of the domains listed in the CN and SAN fields, FortiGate uses the domain in the CN field instead of the domain in the SNI field.
Question
Refer to the exhibit, which shows an SSL certification inspection configuration. Which action does FortiGate take if the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate?
Exhibit
Options
- AFortiGate uses the first entry listed in the SAN field in the server certificate
- BFortiGate uses the CN information from the Subject field in the server certificate
- CFortiGate uses the SNI from the user's web browser.
- DFortiGate closes the connection because this represents an invalid SSL/TLS configuration
How the community answered
(49 responses)- A2% (1)
- B84% (41)
- C6% (3)
- D8% (4)
Explanation
If the domain in the SNI field does not match any of the domains listed in the CN and SAN fields, FortiGate uses the domain in the CN field instead of the domain in the SNI field.
Topics
Community Discussion
No community discussion yet for this question.
