nerdexam
Check_Point

156-215.80 · Question #245

You have configured SNX on the Security Gateway. The client connects to the Security Gateway and the user enters the authentication credentials. What must happen after authentication that allows the…

The correct answer is A. SNX modifies the routing table to forward VPN traffic to the Security Gateway. SNX (SSL Network Extender) modifies the client routing table post-authentication so that traffic destined for the VPN domain is directed through the Security Gateway tunnel.

VPN Solutions

Question

You have configured SNX on the Security Gateway. The client connects to the Security Gateway and the user enters the authentication credentials. What must happen after authentication that allows the client to connect to the Security Gateway's VPN domain?

Options

  • ASNX modifies the routing table to forward VPN traffic to the Security Gateway.
  • BAn office mode address must be obtained by the client.
  • CThe SNX client application must be installed on the client.
  • DActive-X must be allowed on the client.

How the community answered

(23 responses)
  • A
    78% (18)
  • B
    13% (3)
  • C
    4% (1)
  • D
    4% (1)

Why each option

SNX (SSL Network Extender) modifies the client routing table post-authentication so that traffic destined for the VPN domain is directed through the Security Gateway tunnel.

ASNX modifies the routing table to forward VPN traffic to the Security Gateway.Correct

After successful authentication, SNX automatically modifies the client's local routing table to insert routes for the VPN domain, directing matching traffic through the encrypted SSL tunnel to the Security Gateway. This routing change is the core mechanism that enables VPN domain connectivity without a traditional VPN client stack.

BAn office mode address must be obtained by the client.

Office Mode address assignment is a feature of IPsec-based VPN clients, not a requirement for SNX, which operates over SSL and handles routing differently.

CThe SNX client application must be installed on the client.

SNX can be delivered and executed entirely through the browser without a pre-installed application, so prior client installation is not a post-authentication requirement.

DActive-X must be allowed on the client.

SNX supports delivery via Java or a thin client and does not require ActiveX to be enabled on the client.

Concept tested: SNX SSL VPN post-authentication routing mechanism

Source: https://support.checkpoint.com/results/sk/sk65210

Topics

#SNX#SSL Network Extender#routing table#VPN domain

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice