nerdexam
Check_Point

156-215.80 · Question #254

Jennifer McHanry is CEO of ACME. She recently bought her own personal iPad. She wants use her iPad to access the internal Finance Web server. Because the iPad is not a member of the Active Directory…

The correct answer is A. Have the security administrator select the Action field of the Firewall Rule "Redirect HTTP. To enable Captive Portal redirection for unauthenticated users in Check Point Identity Awareness, the firewall rule's Action must be set to redirect HTTP traffic to the Captive Portal.

User Management and Authentication

Question

Jennifer McHanry is CEO of ACME. She recently bought her own personal iPad. She wants use her iPad to access the internal Finance Web server. Because the iPad is not a member of the Active Directory domain, she cannot identify seamlessly with AD Query. However, she can enter her AD credentials in the Captive Portal and then get the same access as on her office computer. Her access to resources is based on rules in the R77 Firewall Rule Base. To make this scenario work, the IT administrator must: 1) Enable Identity Awareness on a gateway and select Captive Portal as one of the Identity Sources. 2) In the Portal Settings window in the User Access section, make sure that Name and password login is selected. 3) Create a new rule in the Firewall Rule Base to let Jennifer McHanry access network destinations. Select accept as the Action. 4) Install policy. Ms McHanry tries to access the resource but is unable. What should she do?

Options

  • AHave the security administrator select the Action field of the Firewall Rule "Redirect HTTP
  • BHave the security administrator reboot the firewall.
  • CHave the security administrator select Any for the Machines tab in the appropriate Access Role.
  • DInstall the Identity Awareness agent on her iPad.

How the community answered

(28 responses)
  • A
    61% (17)
  • B
    14% (4)
  • C
    21% (6)
  • D
    4% (1)

Why each option

To enable Captive Portal redirection for unauthenticated users in Check Point Identity Awareness, the firewall rule's Action must be set to redirect HTTP traffic to the Captive Portal.

AHave the security administrator select the Action field of the Firewall Rule "Redirect HTTPCorrect

Configuring the firewall rule Action to redirect HTTP connections to the Captive Portal is the mechanism that intercepts unauthenticated requests and sends users to the login page. Without this redirect action, the gateway has no way to prompt Jennifer to enter her AD credentials when she browses from her non-domain iPad. This is the step that closes the loop between an Access Role requiring authentication and the browser-based login flow.

BHave the security administrator reboot the firewall.

Rebooting the firewall is not a required or recommended step for enabling Identity Awareness or Captive Portal; a policy install is sufficient to activate new configurations.

CHave the security administrator select Any for the Machines tab in the appropriate Access Role.

Selecting Any for the Machines tab in the Access Role addresses machine-based identity filtering but does not configure the redirect mechanism that prompts Jennifer to authenticate via the portal.

DInstall the Identity Awareness agent on her iPad.

The Identity Awareness agent is a Windows endpoint component used for seamless AD SSO and cannot be installed on an iOS iPad.

Concept tested: Check Point Identity Awareness Captive Portal HTTP redirect configuration

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_IdentityAwareness_AdminGuide/html_frameset.htm

Topics

#captive portal#Identity Awareness#access role#HTTP redirect

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice