156-215.80 · Question #183
Which of the following SSL Network Extender server-side prerequisites is NOT correct?
The correct answer is B. There are distinctly separate access rules required for SecureClient users vs. SSL Network. SSL Network Extender users are governed by the same Remote Access Community access rules as SecureClient users - no separate distinct rule set is required, making option B the incorrect prerequisite statement.
Question
Which of the following SSL Network Extender server-side prerequisites is NOT correct?
Options
- AThe Gateway must be configured to work with Visitor Mode.
- BThere are distinctly separate access rules required for SecureClient users vs. SSL Network
- CTo use Integrity Clientless Security (ICS), you must install the IC3 server or configuration tool.
- DThe specific Security Gateway must be configured as a member of the Remote Access Community
How the community answered
(32 responses)- A3% (1)
- B72% (23)
- C9% (3)
- D16% (5)
Why each option
SSL Network Extender users are governed by the same Remote Access Community access rules as SecureClient users - no separate distinct rule set is required, making option B the incorrect prerequisite statement.
Configuring the gateway for Visitor Mode is a valid and required prerequisite so that SSL Network Extender traffic over TCP port 443 is properly tunneled through the gateway.
This statement is NOT correct because SSL Network Extender users belong to the same Remote Access Community as SecureClient users and are subject to the same unified security policy access rules. Check Point does not require administrators to create separate, distinct rule sets for each client type; both are controlled through the shared Remote Access Community configuration. Claiming separate rules are required is factually incorrect and would mislead administrators.
Installing the IC3 server or configuration tool is a correct prerequisite for enabling Integrity Clientless Security functionality alongside SSL Network Extender.
Adding the Security Gateway as a member of the Remote Access Community is a legitimate and required prerequisite for SSL Network Extender to function on that gateway.
Concept tested: SSL Network Extender server-side prerequisites and community access rules
Source: https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-RAVPNG/SSL-Network-Extender.htm
Topics
Community Discussion
No community discussion yet for this question.