NGFW-ENGINEER · Question #80
A network administrator is establishing a site-to-site VPN between a Palo Alto Networks firewall and a partner's Check Point Security Gateway. The partner has provided a specific list of local and…
The correct answer is A. Define the local and remote subnets provided by the partner in the Proxy ID settings. A policy-based Check Point VPN expects the Phase 2 (Quick Mode) selectors to match specific local and remote subnets, so defining those exact networks as Proxy IDs on the PAN-OS side ensures the negotiated traffic selectors align and allows Phase 2 to complete successfully.
Question
A network administrator is establishing a site-to-site VPN between a Palo Alto Networks firewall and a partner's Check Point Security Gateway. The partner has provided a specific list of local and remote IP address subnets that are permitted through the tunnel. The initial tunnel configuration on the PAN-OS firewall fails during the IKE Phase 2 exchange. Which configuration step is essential to ensure compatibility with the policy-based Check Point gateway?
Options
- ADefine the local and remote subnets provided by the partner in the Proxy ID settings.
- BCreate individual Security policies for each pair of local and remote subnets.
- CAssign a specific IP address to the tunnel interface to match the Check Point gateway.
- DEnable Dead Peer Detection (DPD) in the IKE Gateway configuration.
How the community answered
(19 responses)- A79% (15)
- B11% (2)
- C5% (1)
- D5% (1)
Explanation
A policy-based Check Point VPN expects the Phase 2 (Quick Mode) selectors to match specific local and remote subnets, so defining those exact networks as Proxy IDs on the PAN-OS side ensures the negotiated traffic selectors align and allows Phase 2 to complete successfully.
Topics
Community Discussion
No community discussion yet for this question.