nerdexam
Check_Point

156-215.80 · Question #21

An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both offices are protected by Check Point Security Gateway managed by the same Security…

The correct answer is C. Certificate based Authentication is the only authentication method available between two Security. When both Check Point Security Gateways are managed by the same Security Management Server, certificate-based authentication is the only available VPN authentication method and the pre-shared secret option is grayed out.

VPN Solutions

Question

An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both offices are protected by Check Point Security Gateway managed by the same Security Management Server. While configuring the VPN community to specify the pre-shared secret the administrator found that the check box to enable pre-shared secret is shared and cannot be enabled. Why does it not allow him to specify the pre-shared secret?

Options

  • AIPsec VPN blade should be enabled on both Security Gateway.
  • BPre-shared can only be used while creating a VPN between a third party vendor and Check Point
  • CCertificate based Authentication is the only authentication method available between two Security
  • DThe Security Gateways are pre-R75.40.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    15% (6)
  • C
    75% (30)
  • D
    8% (3)

Why each option

When both Check Point Security Gateways are managed by the same Security Management Server, certificate-based authentication is the only available VPN authentication method and the pre-shared secret option is grayed out.

AIPsec VPN blade should be enabled on both Security Gateway.

The IPsec VPN blade must be enabled on both gateways for VPN to function at all, but this is a prerequisite for the feature rather than a factor that controls which authentication methods are available in the VPN community.

BPre-shared can only be used while creating a VPN between a third party vendor and Check Point

Pre-shared secret is indeed available when connecting to a third-party vendor - this answer describes the scenario where pre-shared secret IS allowed, which is the inverse of why it is unavailable in the same-SMS scenario described.

CCertificate based Authentication is the only authentication method available between two SecurityCorrect

The Security Management Server acts as the internal Certificate Authority for all gateways it manages, so when both VPN peers belong to the same SMS, trusted certificates are automatically issued and certificate-based authentication is enforced. Pre-shared secret is only available when at least one peer is a third-party device or is managed by a different management server, because in those cases the shared CA trust cannot be assumed.

DThe Security Gateways are pre-R75.40.

The R75.40 gateway version threshold is not related to the authentication method restriction - the restriction is determined solely by whether both gateways share the same Security Management Server, regardless of gateway version.

Concept tested: Check Point site-to-site VPN authentication method with shared SMS

Source: https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_VPN_AdminGuide/Topics/Configuring-VPN-Communities.htm

Topics

#IPsec VPN#pre-shared secret#certificate authentication#VPN community

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice