Question 141

Refer to the exhibit, which shows an SSL certification inspection configuration.
SSL certification inspection configuration

While testing, the administrator updated the ssl-ssh-profile configuration with the command set sni-server-cert-check strict.
The administrator found that the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.
With respect to the set sni-server-cert-check strict command, which action does FortiGate take?
  • Question 142

    A user reports that their computer was infected with malware after accessing a secured HTTPS website.
    However, when you check the FortiGate logs, you see that FortiGate did not detect the website as insecure, despite having an SSL certificate and the correct profiles applied on the policy.
    How can you ensure that FortiGate can analyze encrypted HTTPS traffic on a website?
  • Question 143

    Refer to the exhibit, which shows a network diagram.

    An administrator would like to modify the MED value advertised from FortiGate_1 to a BGP neighbor in the autonomous system 30.
    What must the administrator configure on FortiGate_1 to implement this?
  • Question 144

    Refer to the exhibits. The exhibits show a network topology, a firewall policy, and an SSL/SSH inspection profile configuration.


    Why is FortiGate unable to detect HTTPS attacks on firewall policy ID 3 targeting the Linux server?
  • Question 145

    Refer to the exhibit, which shows a hub and spokes deployment.

    An administrator is deploying several spokes, including the BGP configuration for the spokes to connect to the hub.
    Which two commands allow the administrator to minimize the configuration? (Choose two.)