156-215.80 · Question #345
In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?
The correct answer is C. SND is used to distribute packets among Firewall instances. SND (Secure Network Distributor) is a Check Point CoreXL component that distributes incoming packets across multiple Firewall Worker instances to enable parallel processing on multi-core gateways.
Question
In what way is Secure Network Distributor (SND) a relevant feature of the Security Gateway?
Options
- ASND is a feature to accelerate multiple SSL VPN connections
- BSND is an alternative to IPSec Main Mode, using only 3 packets
- CSND is used to distribute packets among Firewall instances
- DSND is a feature of fw monitor to capture accelerated packets
How the community answered
(54 responses)- B4% (2)
- C94% (51)
- D2% (1)
Why each option
SND (Secure Network Distributor) is a Check Point CoreXL component that distributes incoming packets across multiple Firewall Worker instances to enable parallel processing on multi-core gateways.
SND distributes all types of network traffic among FW instances and is not specific to or designed for SSL VPN connection acceleration.
The 3-packet exchange describes IKE Aggressive Mode, which is an alternative to IKE Main Mode's 6-packet exchange - this is an IPSec concept unrelated to SND.
SND is the CoreXL mechanism that inspects incoming packets and assigns them to the appropriate Firewall Worker (FW) instance based on connection attributes such as source IP, destination IP, and port. This distribution allows multiple CPU cores to process separate connections simultaneously, significantly increasing throughput on multi-core Security Gateways.
fw monitor is a dedicated packet capture and inspection utility; SND is a CoreXL traffic distribution component and is not a feature of fw monitor.
Concept tested: Check Point CoreXL SND packet distribution among FW instances
Source: https://support.checkpoint.com/results/sk/sk98737
Topics
Community Discussion
No community discussion yet for this question.