nerdexam
Fortinet

NSE8_812 · Question #42

A FortiGate cluster (CL-1) protects a data center hosting multiple web applications. A pair of FortiADC devices are already configured for SSL decryption (FAD-1), and re-encryption (FAD-2). CL-1…

The correct answer is A. config firewall profile-protocol-options edit SSL-Offload config http set ssl-offloaded yes next end end D. config application list edit SSL-Offload-App-Detect set deep-app-inspection enable next end. See the full explanation below for the reasoning.

Question

A FortiGate cluster (CL-1) protects a data center hosting multiple web applications. A pair of FortiADC devices are already configured for SSL decryption (FAD-1), and re-encryption (FAD-2). CL-1 must accept unencrypted traffic from FAD-1, perform application detection on the plain-text traffic, and forward the inspected traffic to FAD-2. The SSL-Offload-App-Detect application list and SSL-Offload protocol options profile are applied to the firewall policy handling the web application traffic on CL-1. Given this scenario, which two configuration tasks must the administrator perform on CL-1? (Choose two.)

Options

  • Aconfig firewall profile-protocol-options edit SSL-Offload config http set ssl-offloaded yes next end end
  • Bconfig firewall ssl-server edit FAD-1 set ip <FAD-1 IP address> set ssl-mode full next end
  • Cconfig application list edit SSL-Offload-App-Detect set force-inclusion-ssl-di-sigs enable next end
  • Dconfig application list edit SSL-Offload-App-Detect set deep-app-inspection enable next end
  • Econfig application list edit SSL-Offload-App-Detect set deep-app-inspection enable next end

How the community answered

(25 responses)
  • A
    72% (18)
  • B
    4% (1)
  • C
    16% (4)
  • E
    8% (2)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice