The correct answers are C and D. Once the SSL proxy profile already exists, the SRX still needs a security policy that matches the SSL/TLS traffic and applies the SSL proxy profile as an application service. Juniper’s SSL proxy configuration procedure explicitly shows creating the security policy match criteria and then applying the SSL proxy profile with then permit application-services ssl-proxy profile-name. It also states that SSL forward and reverse proxy require the profile to be configured at the firewall rule level.
Option D is correct because SSL proxy is not an end goal by itself; it decrypts SSL/TLS traffic so Layer 7 security services can inspect it. Juniper states that decrypted SSL traffic is available for security services and provides examples where the SSL proxy profile and a Content Security/UTM policy are both attached to the same security policy. Option A is wrong because host-inbound-traffic HTTPS controls HTTPS access to the SRX itself, not transit SSL proxy inspection. Option B is wrong because SSL proxy profiles are not referenced under a security zone for this function; they are applied under the matching security policy. Reference topics: SSL Proxy, SSL proxy profile, security policy application-services, Layer 7 inspection, UTM/IDP/ATP integration.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit