An enterprise network administrator is deploying a next-generation firewall (NGFW) to inspect encrypted traffic. Which architecture allows the NGFW to decrypt and inspect inbound HTTPS traffic destined for internal web servers without compromising private keys on every server?
Trap 1: SSL Forward Proxy inspection
SSL Forward Proxy is designed for outbound traffic where internal clients browse the external internet. It intercepts outbound TLS connections by dynamically signing certificates with a local forward trust certificate, which does not address inbound connections to internal web servers.
Trap 2: SSH Proxy tunneling with asymmetric key exchange
SSH proxy tunneling is specifically built for secure shell remote management traffic and administrative file transfers. It does not handle inbound HTTPS web traffic inspection or TLS handshake termination for standard web applications.
Trap 3: Transparent proxy mode without certificate installation
Transparent proxy mode intercepts TCP traffic at Layer 3 or 4 without modifying IP addresses, but it cannot decrypt TLS traffic without access to the corresponding private keys or a trusted enterprise certificate authority infrastructure.
- A
SSL Forward Proxy inspection
Why it fails: SSL Forward Proxy is designed for outbound traffic where internal clients browse the external internet. It intercepts outbound TLS connections by dynamically signing certificates with a local forward trust certificate, which does not address inbound connections to internal web servers.
- B
Inbound SSL Decryption utilizing the server private key on the firewall
Deploying the server private key on the firewall allows the device to act as a proxy for inbound traffic. It decrypts the TLS stream for security inspection before forwarding traffic to the backend server, protecting internal applications from application-layer threats.
- C
SSH Proxy tunneling with asymmetric key exchange
Why it fails: SSH proxy tunneling is specifically built for secure shell remote management traffic and administrative file transfers. It does not handle inbound HTTPS web traffic inspection or TLS handshake termination for standard web applications.
- D
Transparent proxy mode without certificate installation
Why it fails: Transparent proxy mode intercepts TCP traffic at Layer 3 or 4 without modifying IP addresses, but it cannot decrypt TLS traffic without access to the corresponding private keys or a trusted enterprise certificate authority infrastructure.