nerdexam
Check_Point

156-836 · Question #26

When a VPN tunnel is formed with a Maestro SGM?

The correct answer is B. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's. Below is a flow of hosts behind a Maestro Security Group. The host opens a clear connection to the other side over the Internet: 1. The host opens a connection and sends a clear packet to the uplink of the Orchestrator. 2. The Orchestrator distributes it accordingly to a clear…

Advanced Maestro Features

Question

When a VPN tunnel is formed with a Maestro SGM?

Options

  • AThe receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup
  • BSGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's
  • CThe MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic.
  • DThe MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the

How the community answered

(41 responses)
  • A
    17% (7)
  • B
    71% (29)
  • C
    5% (2)
  • D
    7% (3)

Explanation

Below is a flow of hosts behind a Maestro Security Group. The host opens a clear connection to the other side over the Internet: 1. The host opens a connection and sends a clear packet to the uplink of the Orchestrator. 2. The Orchestrator distributes it accordingly to a clear packet IP address and sends it to one of the SGMs (SGM 1, for example). 3. SGM 1 checks policy and topology. If encryption is required, it calculates the tunnel owner's IP 4. SGM 1 sends a clear packet to the tunnel owner (SGM 2, for example). From this moment, SGM 2 is the connection and tunnel owner. 5. SGM 2 syncs two backup SGMs: - one for clear (Client 2 Server - calculated accordingly to clear IP) - one for encrypted (Server 2 Client - calculated accordingly to tunnel IPs) - Note: Backup SGMs might be the same for both directions (depends on "dxl calc"). 6. When receiving a reply, it arrives encrypted to SGM 2, and is sent directly to the host after

Topics

#VPN tunnel#encryption#tunnel owner#SGM traffic handling

Community Discussion

No community discussion yet for this question.

Full 156-836 Practice