156-215.80 · Question #245
You have configured SNX on the Security Gateway. The client connects to the Security Gateway and the user enters the authentication credentials. What must happen after authentication that allows the…
The correct answer is A. SNX modifies the routing table to forward VPN traffic to the Security Gateway. SNX (SSL Network Extender) modifies the client routing table post-authentication so that traffic destined for the VPN domain is directed through the Security Gateway tunnel.
Question
You have configured SNX on the Security Gateway. The client connects to the Security Gateway and the user enters the authentication credentials. What must happen after authentication that allows the client to connect to the Security Gateway's VPN domain?
Options
- ASNX modifies the routing table to forward VPN traffic to the Security Gateway.
- BAn office mode address must be obtained by the client.
- CThe SNX client application must be installed on the client.
- DActive-X must be allowed on the client.
How the community answered
(23 responses)- A78% (18)
- B13% (3)
- C4% (1)
- D4% (1)
Why each option
SNX (SSL Network Extender) modifies the client routing table post-authentication so that traffic destined for the VPN domain is directed through the Security Gateway tunnel.
After successful authentication, SNX automatically modifies the client's local routing table to insert routes for the VPN domain, directing matching traffic through the encrypted SSL tunnel to the Security Gateway. This routing change is the core mechanism that enables VPN domain connectivity without a traditional VPN client stack.
Office Mode address assignment is a feature of IPsec-based VPN clients, not a requirement for SNX, which operates over SSL and handles routing differently.
SNX can be delivered and executed entirely through the browser without a pre-installed application, so prior client installation is not a post-authentication requirement.
SNX supports delivery via Java or a thin client and does not require ActiveX to be enabled on the client.
Concept tested: SNX SSL VPN post-authentication routing mechanism
Source: https://support.checkpoint.com/results/sk/sk65210
Topics
Community Discussion
No community discussion yet for this question.