156-561 · Question #51
Which software blades (Check Point features) are not supported in AWS?
The correct answer is D. Mobile Access (SSLVPN). Mobile Access (SSL VPN) is not supported in AWS CloudGuard deployments because it requires direct client-to-gateway connectivity that conflicts with AWS's elastic load balancing and NAT architectures - remote users cannot reliably establish SSL VPN tunnels to a dynamically…
Question
Which software blades (Check Point features) are not supported in AWS?
Options
- AIPS
- BVPN blade
- CAll Check Point blades are supported
- DMobile Access (SSLVPN)
How the community answered
(52 responses)- A2% (1)
- B4% (2)
- C2% (1)
- D92% (48)
Explanation
Mobile Access (SSL VPN) is not supported in AWS CloudGuard deployments because it requires direct client-to-gateway connectivity that conflicts with AWS's elastic load balancing and NAT architectures - remote users cannot reliably establish SSL VPN tunnels to a dynamically addressed cloud instance in the same way they would to a physical edge appliance.
Why the distractors are wrong:
- A (IPS): Fully supported; CloudGuard in AWS uses IPS for inline threat prevention on traffic traversing the gateway.
- B (VPN blade): Site-to-site VPN is supported and commonly used to connect AWS VPCs back to on-prem networks.
- C (All blades supported): Incorrect - Mobile Access being unsupported disproves this.
Memory tip: Think "Mobile Access needs a front door" - it's designed for users knocking on a physical corporate perimeter. AWS CloudGuard sits inside the cloud with no stable "front door" for end-user SSL VPN clients, so Mobile Access doesn't apply there.
Topics
Community Discussion
No community discussion yet for this question.