Fortinet
NSE8_812 · Question #42
A FortiGate cluster (CL-1) protects a data center hosting multiple web applications. A pair of FortiADC devices are already configured for SSL decryption (FAD-1), and re-encryption (FAD-2). CL-1…
The correct answer is A. config firewall profile-protocol-options edit SSL-Offload config http set ssl-offloaded yes next end end D. config application list edit SSL-Offload-App-Detect set deep-app-inspection enable next end. See the full explanation below for the reasoning.
Question
A FortiGate cluster (CL-1) protects a data center hosting multiple web applications. A pair of FortiADC devices are already configured for SSL decryption (FAD-1), and re-encryption (FAD-2). CL-1 must accept unencrypted traffic from FAD-1, perform application detection on the plain-text traffic, and forward the inspected traffic to FAD-2. The SSL-Offload-App-Detect application list and SSL-Offload protocol options profile are applied to the firewall policy handling the web application traffic on CL-1. Given this scenario, which two configuration tasks must the administrator perform on CL-1? (Choose two.)
Options
- Aconfig firewall profile-protocol-options edit SSL-Offload config http set ssl-offloaded yes next end end
- Bconfig firewall ssl-server edit FAD-1 set ip <FAD-1 IP address> set ssl-mode full next end
- Cconfig application list edit SSL-Offload-App-Detect set force-inclusion-ssl-di-sigs enable next end
- Dconfig application list edit SSL-Offload-App-Detect set deep-app-inspection enable next end
- Econfig application list edit SSL-Offload-App-Detect set deep-app-inspection enable next end
How the community answered
(25 responses)- A72% (18)
- B4% (1)
- C16% (4)
- E8% (2)
Community Discussion
No community discussion yet for this question.