ExamGecko
Question list
Search
Search

Question 292 - 156-315.81 discussion

Report
Export

After trust has been established between the Check Point components, what is TRUE about name and IP-address changes?

A.
Security Gateway IP-address cannot be changed without re-establishing the trust.
Answers
A.
Security Gateway IP-address cannot be changed without re-establishing the trust.
B.
The Security Gateway name cannot be changed in command line without re-establishing trust.
Answers
B.
The Security Gateway name cannot be changed in command line without re-establishing trust.
C.
The Security Management Server name cannot be changed in SmartConsole without re-establishing trust.
Answers
C.
The Security Management Server name cannot be changed in SmartConsole without re-establishing trust.
D.
The Security Management Server IP-address cannot be changed without re-establishing the trust.
Answers
D.
The Security Management Server IP-address cannot be changed without re-establishing the trust.
Suggested answer: A

Explanation:

After trust has been established between the Check Point components, the Security Gateway IP address cannot be changed without re-establishing the trust. This is because the trust is based on the Secure Internal Communication (SIC) mechanism, which uses certificates to authenticate and encrypt the communication. The certificates are issued by the Internal Certificate Authority (ICA) of the Security Management Server / Domain Management Server, and contain the name and IP address of the component. Therefore, if the IP address of a component is changed, the certificate will become invalid and the trust will be lost.To restore the trust, the certificate must be renewed or reissued by the ICA12.

However, there are some exceptions to this rule. The Security Gateway name can be changed in command line without re-establishing trust, as long as the IP address remains the same. This is because the SIC mechanism does not rely on the hostname, but on the IP address and the SIC name (which is usually derived from the hostname, but can be manually changed). The Security Management Server name can be changed in SmartConsole without re-establishing trust, as long as the IP address remains the same. This is because SmartConsole uses a different mechanism to connect to the Security Management Server, which does not depend on the SIC certificate. The Security Management Server IP address can be changed without re-establishing trust, as long as some steps are followed to update the Check Point Registry file on the managed Security Gateways / Cluster Members / VSX Virtual Devices. This is because the Registry file contains the IP address of the ICA, which is used for certificate renewal.If the Registry file is not updated, then the certificate renewal will fail and the trust will be lost3.

asked 16/09/2024
Dennis Bruyn
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first