156-215.80 · Question #542
Which option in a firewall rule would only match and allow traffic to VPN gateways for one Community in common?
The correct answer is C. Specific VPN Communities. The 'Specific VPN Communities' option in a firewall rule restricts traffic matching to gateways belonging to one explicitly designated VPN community only.
Question
Which option in a firewall rule would only match and allow traffic to VPN gateways for one Community in common?
Options
- AAll Connections (Clear or Encrypted)
- BAccept all encrypted traffic
- CSpecific VPN Communities
- DAll Site-to-Site VPN Communities
How the community answered
(42 responses)- A14% (6)
- B7% (3)
- C74% (31)
- D5% (2)
Why each option
The 'Specific VPN Communities' option in a firewall rule restricts traffic matching to gateways belonging to one explicitly designated VPN community only.
'All Connections (Clear or Encrypted)' matches all network traffic regardless of encryption or VPN community membership, making it far too broad for this use case.
'Accept all encrypted traffic' matches any encrypted VPN traffic across all communities, not limiting the rule to a single specified community.
Selecting 'Specific VPN Communities' allows the administrator to name a single VPN community, so the firewall rule only matches and allows traffic destined for or originating from gateways that are members of that one community. This provides granular control, ensuring the rule does not apply to other communities or unencrypted traffic.
'All Site-to-Site VPN Communities' applies the rule to every site-to-site VPN community configured, not just one specific community.
Concept tested: Check Point VPN community-specific firewall rule matching
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Topics-SMAG/VPN-Communities.htm
Topics
Community Discussion
No community discussion yet for this question.