I hace an SFTP server in my DMZ. There's a DNAT entry and firewall policy allowing access from Internet IPV4 using port 22 to the server. No other ports are open. No SSL cert is installed on the server.
When we run a Pen test from outside the company, it's throwing a bunch of SSL errors.
SSL Certificate Cannot Be Trusted, SSL Certificate with Wrong Hostname, SSL Self-Signed Certificate
Turns out, the scanner is returning info from the UTM's SSL cert. How do I fix this?
This thread was automatically locked due to age.