Which two statements are accurate about client-protection Secure Socket Layer (SSL) proxy configurations?
A client-protection SSL proxy is a forward proxy. Its profile requires a configured root CA so the firewall can generate and sign certificates presented to internal clients, while a server certificate is not configured. Juniper documents the supported forward-proxy combination as root-ca configured and server-certificate not configured.
root-ca
server-certificate
Community Discussion