156-215.80 · Question #400
Which configuration element determines which traffic should be encrypted into a VPN tunnel vs. sent in the clear?
The correct answer is C. The Rule Base. In Check Point VPN architecture, the Rule Base (the set of security rules in the policy) is what ultimately determines the action taken on traffic - including whether it should be encrypted (action: VPN encrypt) or allowed in the clear (action: Accept). VPN Domains (D) define…
Question
Which configuration element determines which traffic should be encrypted into a VPN tunnel vs. sent in the clear?
Options
- AThe firewall topologies
- BNAT Rules
- CThe Rule Base
- DThe VPN Domains
How the community answered
(52 responses)- A4% (2)
- B6% (3)
- C81% (42)
- D10% (5)
Explanation
In Check Point VPN architecture, the Rule Base (the set of security rules in the policy) is what ultimately determines the action taken on traffic - including whether it should be encrypted (action: VPN encrypt) or allowed in the clear (action: Accept). VPN Domains (D) define which hosts/networks are considered 'inside' a VPN community and are used to build the encryption domains, but they do not by themselves decide per-traffic encryption vs. clear-text behavior. The Rule Base ties together the source, destination, service, and action - so a rule can explicitly direct matched traffic into a VPN tunnel or bypass it. NAT Rules (B) handle address translation, not encryption decisions. Firewall topologies (A) is not a standard configuration element for this purpose.
Topics
Community Discussion
No community discussion yet for this question.