QuestionQ18
Network Security Support EngineerConsider a situation in which the server name indication (SNI) does not match either the common name (CN) or any subject alternative name (SAN) in the server certificate.
With the default SSL certificate-inspection settings, what action will FortiGate take?
- A FortiGate closes the connection because this represents an invalid SSL/TLS configuration.
- B FortiGate uses the CN information from the Subject field in the server certificate.
- C FortiGate uses the first entry listed in the SAN field in the server certificate.
- D FortiGate uses the SNI from the user’s web browser.
Community Discussion