ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 34 - NSE8_812 discussion

Report
Export

Refer to the CLI configuration of an SSL inspection profile from a FortiGate device configured to protect a web server:

Based on the information shown, what is the expected behavior when an HTTP/2 request comes in?

A.
FortiGate will reject all HTTP/2 ALPN headers.
Answers
A.
FortiGate will reject all HTTP/2 ALPN headers.
B.
FortiGate will strip the ALPN header and forward the traffic.
Answers
B.
FortiGate will strip the ALPN header and forward the traffic.
C.
FortiGate will rewrite the ALPN header to request HTTP/1.
Answers
C.
FortiGate will rewrite the ALPN header to request HTTP/1.
D.
FortiGate will forward the traffic without modifying the ALPN header.
Answers
D.
FortiGate will forward the traffic without modifying the ALPN header.
Suggested answer: B

Explanation:

When an HTTP/2 request comes in, FortiGate will strip the Application-Layer Protocol Negotiation (ALPN) header and forward the traffic as HTTP/1.1 to the real server. This is because FortiGate does not support HTTP/2 inspection, and therefore cannot process ALPN headers that indicate HTTP/2 support. Reference:

https://docs.fortinet.com/document/fortigate/6.4.0/cookbook/103438/application-detection-on-ssloffloaded-traffic

asked 18/09/2024
Gofaone Ncube
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first