nerdexam
Check_Point

156-215.80 · Question #502

Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?

The correct answer is B. Accept all encrypted traffic. In Check Point Security Policy, the VPN column option 'Accept all encrypted traffic' instructs a rule to match all encrypted VPN traffic regardless of community membership, while still permitting clear non-VPN connections to match the same rule.

VPN Solutions

Question

Which option, when applied to a rule, allows all encrypted and non-VPN traffic that matches the rule?

Options

  • AAll Site-to-Site VPN Communities
  • BAccept all encrypted traffic
  • CAll Connections (Clear or Encrypted)
  • DSpecific VPN Communities

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    90% (38)
  • C
    2% (1)
  • D
    2% (1)

Why each option

In Check Point Security Policy, the VPN column option 'Accept all encrypted traffic' instructs a rule to match all encrypted VPN traffic regardless of community membership, while still permitting clear non-VPN connections to match the same rule.

AAll Site-to-Site VPN Communities

All Site-to-Site VPN Communities restricts the rule to only site-to-site VPN traffic, excluding clear non-VPN connections.

BAccept all encrypted trafficCorrect

When 'Accept all encrypted traffic' is set in a rule's VPN column, the Security Gateway applies that rule's action to all incoming encrypted traffic from any VPN community without restriction. This differs from community-specific options because it does not limit matching to a predefined set of communities, and clear traffic can also match the rule through normal rule base processing - covering both encrypted and non-VPN traffic as the question describes.

CAll Connections (Clear or Encrypted)

All Connections (Clear or Encrypted) is not a distinct named VPN column option in the Check Point rule base in the way the question describes it.

DSpecific VPN Communities

Specific VPN Communities limits the rule to traffic matching only the explicitly chosen communities, excluding all other encrypted and non-VPN traffic.

Concept tested: Check Point Security Policy VPN column rule options

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/VPN-in-the-Rule-Base.htm

Topics

#VPN rule#encrypted traffic#VPN communities#rule base

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice