156-215.80 · Question #252
Which of the following firewall modes DOES NOT allow for Identity Awareness to be deployed?
The correct answer is A. Bridge. Bridge (transparent) mode operates at Layer 2 without a routable IP address on inspected segments, which is incompatible with Identity Awareness's Layer 3 requirements.
Question
Which of the following firewall modes DOES NOT allow for Identity Awareness to be deployed?
Options
- ABridge
- BLoad Sharing
- CHigh Availability
- DFail Open
How the community answered
(40 responses)- A73% (29)
- B15% (6)
- C8% (3)
- D5% (2)
Why each option
Bridge (transparent) mode operates at Layer 2 without a routable IP address on inspected segments, which is incompatible with Identity Awareness's Layer 3 requirements.
In Bridge mode the Security Gateway acts as a Layer 2 bridge and does not hold an IP address on the monitored network segments. Identity Awareness requires Layer 3 connectivity to reach Active Directory domain controllers for identity queries and to intercept identity-bearing traffic, so it cannot be deployed on a gateway running in Bridge mode.
Load Sharing is a ClusterXL mode where multiple active gateways divide traffic; Identity Awareness is fully supported and synchronizes identity tables across cluster members.
High Availability is a ClusterXL mode with an active and standby gateway; Identity Awareness is supported and identity mappings are maintained across failover events.
Fail Open is a bypass behavior that passes traffic uninspected during a gateway failure; it does not structurally prevent Identity Awareness from being deployed during normal operation.
Concept tested: Identity Awareness incompatibility with Bridge transparent mode
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_IdentityAwareness_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.