156-215.80 · Question #502
Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?
The correct answer is B. Accept all encrypted traffic. In Check Point Security Policy, the VPN column option 'Accept all encrypted traffic' instructs a rule to match all encrypted VPN traffic regardless of community membership, while still permitting clear non-VPN connections to match the same rule.
Question
Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?
Options
- AAll Site-to-Site VPN Communities
- BAccept all encrypted traffic
- CAll Connections (Clear or Encrypted)
- DSpecific VPN Communities
How the community answered
(42 responses)- A5% (2)
- B90% (38)
- C2% (1)
- D2% (1)
Why each option
In Check Point Security Policy, the VPN column option 'Accept all encrypted traffic' instructs a rule to match all encrypted VPN traffic regardless of community membership, while still permitting clear non-VPN connections to match the same rule.
All Site-to-Site VPN Communities restricts the rule to only site-to-site VPN traffic, excluding clear non-VPN connections.
When 'Accept all encrypted traffic' is set in a rule's VPN column, the Security Gateway applies that rule's action to all incoming encrypted traffic from any VPN community without restriction. This differs from community-specific options because it does not limit matching to a predefined set of communities, and clear traffic can also match the rule through normal rule base processing - covering both encrypted and non-VPN traffic as the question describes.
All Connections (Clear or Encrypted) is not a distinct named VPN column option in the Check Point rule base in the way the question describes it.
Specific VPN Communities limits the rule to traffic matching only the explicitly chosen communities, excluding all other encrypted and non-VPN traffic.
Concept tested: Check Point Security Policy VPN column rule options
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/VPN-in-the-Rule-Base.htm
Topics
Community Discussion
No community discussion yet for this question.