Which action will FortiGate take when using the default settings for SSL certificate inspection, where the server name indication (SNI) does not match either the common name (CN) or any of the subject altemative names (SAN) in the server certificate?
#Config firewall ssl-ssh-profile
edit
config https
set sni-server-cert-check [enable* | strict | disable]
Enable: If the SNI does NOT match the CN or SAN fields in the returned server's certificate, FG uses the CN field instead of the SNI to obtain the FQDN.
Strict: If the SNI does NOT match the CN or SAN fields in the returned server's certificate, FG closes the connection.
Disable: FG does not check the SNI.
Malinda
7 months agoBarbra
7 months agoAshlee
7 months agoDannie
7 months agoMira
7 months agoKaycee
7 months agoSocorro
7 months agoJamal
7 months ago