156-315.71 · Question #33
You have three Gateways in a mesh community. Each gateway's VPN Domain is their internal network as defined on the Topology tab setting All IP Addresses behind Gateway based on Topology information…
The correct answer is B. Domain VPN takes precedence over the route-based VTI. To make the VPN go through VTI, use. See the full explanation below for the reasoning.
Question
You have three Gateways in a mesh community. Each gateway's VPN Domain is their internal network as defined on the Topology tab setting All IP Addresses behind Gateway based on Topology information. You want to test the route-based VPN, so you created VTls among the Gateways and created static route entries for the VTIs. However, when you test the VPN, you find out the VPN still go through the regular domain IPSec tunnels instead of the routed VTI tunnels. What is the problem and how do you make the VPN use the VTI tunnels? Check Point 156-315.71 Exam
Options
- ARoute-based VTI takes precedence over the Domain VPN. Troubleshoot the static route entries to
- BDomain VPN takes precedence over the route-based VTI. To make the VPN go through VTI, use
- CDomain VPN takes precedence over the route-based VTI. To make the VPN go through VTI, remove
- DRoute-based VTI takes precedence over the Domain VPN. To make the VPN go through VTI,use
How the community answered
(23 responses)- A4% (1)
- B78% (18)
- C13% (3)
- D4% (1)
Community Discussion
No community discussion yet for this question.