QuestionQ54

VPN

A user reports that their computer became infected with malware after visiting a secured HTTPS website. However, when you review the FortiGate logs, FortiGate did not identify the website as insecure, despite its SSL certificate and the correct profiles being applied to the policy.

How can you ensure that FortiGate can analyze encrypted HTTPS traffic on a website?

  • A Enable server certificate SNI check to protect against unsecured HTTPS websites.
  • B Set min-allowed-ssl-version to tls-1.2.
  • C Enable full SSL inspection in the SSL/SSH Inspection profile to decrypt packets.
  • D Set inspection-mode to proxy.
Explanation

Full SSL inspection decrypts SSL/TLS traffic so FortiGate security profiles can inspect the HTTPS payload for threats such as malware. Certificate checks and TLS, SNI, or inspection-mode settings alone do not provide decrypted payload inspection.

Community Discussion

No comments yet. Be the first to start the discussion!