nerdexam
Check_Point

156-215.80 · Question #257

A client has created a new Gateway object that will be managed at a remote location. When the client attempts to install the Security Policy to the new Gateway object, the object does not appear in…

The correct answer is B. A Gateway object created using the Check Point > Externally Managed VPN Gateway option from. A Gateway object created as an Externally Managed VPN Gateway is not managed by the local Security Management Server, so it does not appear as a valid target in the Install On field.

Deployment and Configuration

Question

A client has created a new Gateway object that will be managed at a remote location. When the client attempts to install the Security Policy to the new Gateway object, the object does not appear in the Install On check box. What should you look for?

Options

  • ASecure Internal Communications (SIC) not configured for the object.
  • BA Gateway object created using the Check Point > Externally Managed VPN Gateway option from
  • CAnti-spoofing not configured on the interfaces on the Gateway object.
  • DA Gateway object created using the Check Point > Secure Gateway option in the network objects,

How the community answered

(17 responses)
  • A
    18% (3)
  • B
    71% (12)
  • C
    6% (1)
  • D
    6% (1)

Why each option

A Gateway object created as an Externally Managed VPN Gateway is not managed by the local Security Management Server, so it does not appear as a valid target in the Install On field.

ASecure Internal Communications (SIC) not configured for the object.

Missing SIC would cause a communication error during the installation attempt, not prevent the object from appearing in the Install On list.

BA Gateway object created using the Check Point > Externally Managed VPN Gateway option fromCorrect

When a gateway is created using the 'Externally Managed VPN Gateway' option, Check Point treats it as a third-party or remotely administered device outside the local SMS's management scope. Because the local SMS does not control this object directly, it is excluded from the Install On checkbox during policy installation. Only gateways managed by the local SMS are eligible targets for policy push.

CAnti-spoofing not configured on the interfaces on the Gateway object.

Anti-spoofing is a traffic inspection setting on interfaces and has no effect on whether a gateway object appears in the Install On checkbox.

DA Gateway object created using the Check Point > Secure Gateway option in the network objects,

A gateway created via the 'Secure Gateway' option is locally managed and would correctly appear in the Install On checkbox.

Concept tested: Check Point Externally Managed VPN Gateway policy installation eligibility

Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SMAG/Gateways-and-Servers.htm

Topics

#gateway object#policy installation#externally managed gateway#SIC

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice