nerdexam
Check_Point

156-215.80 · Question #528

You have created a rule at the top of your Rule Base to permit Guest Wireless access to the Internet. However, when guest users attempt to reach the Internet, they are not seeing the splash page to…

The correct answer is A. Right click Accept in the rule, select "More", and then check "Enable Identity Captive Portal". Captive Portal for a specific firewall rule must be enabled directly on that rule's Accept action, not in global or object-level settings.

User Management and Authentication

Question

You have created a rule at the top of your Rule Base to permit Guest Wireless access to the Internet. However, when guest users attempt to reach the Internet, they are not seeing the splash page to accept your Terms of Service, and cannot access the Internet. How can you fix this?

Options

  • ARight click Accept in the rule, select "More", and then check "Enable Identity Captive Portal"
  • BOn the firewall object, Legacy Authentication screen, check "Enable Identity Captive Portal"
  • CIn the Captive Portal screen of Global Properties, check "Enable Identity Captive Portal"
  • DOn the Security Management Server object, check the box "Identity Logging"

How the community answered

(31 responses)
  • A
    81% (25)
  • B
    3% (1)
  • C
    6% (2)
  • D
    10% (3)

Why each option

Captive Portal for a specific firewall rule must be enabled directly on that rule's Accept action, not in global or object-level settings.

ARight click Accept in the rule, select "More", and then check "Enable Identity Captive Portal"Correct

In Check Point SmartConsole, Captive Portal is enabled on a per-rule basis by right-clicking the Accept action, choosing 'More', and enabling 'Enable Identity Captive Portal'. This ties the splash page challenge to the specific rule governing guest traffic, ensuring users are redirected before being granted access.

BOn the firewall object, Legacy Authentication screen, check "Enable Identity Captive Portal"

The firewall object's Legacy Authentication screen controls authentication methods for the gateway itself, not per-rule Captive Portal enforcement.

CIn the Captive Portal screen of Global Properties, check "Enable Identity Captive Portal"

Global Properties contains general Identity Awareness settings, but enabling Captive Portal globally does not activate it for a specific rule - it must be set at the rule's action level.

DOn the Security Management Server object, check the box "Identity Logging"

'Identity Logging' on the Security Management Server controls log enrichment with identity data, not the enforcement of a Captive Portal splash page.

Concept tested: Check Point per-rule Captive Portal configuration

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Configuring-Captive-Portal.htm

Topics

#Captive Portal#Identity Awareness#guest wireless#Terms of Service

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice