ExamGecko
Question list
Search
Search

Question 338 - 156-315.81 discussion

Report
Export

An administrator is creating an IPsec site-to-site VPN between his corporate office and branch office. Both offices are protected by Check Point Security Gateway managed by the same Security Management Server. While configuring the VPN community to specify the pre-shared secret the administrator found that the check box to enable pre-shared secret and cannot be enabled.

Why does it not allow him to specify the pre-shared secret?

A.
IPsec VPN blade should be enabled on both Security Gateway.
Answers
A.
IPsec VPN blade should be enabled on both Security Gateway.
B.
Pre-shared can only be used while creating a VPN between a third party vendor and Check Point Security Gateway.
Answers
B.
Pre-shared can only be used while creating a VPN between a third party vendor and Check Point Security Gateway.
C.
Certificate based Authentication is the only authentication method available between two Security Gateway managed by the same SMS.
Answers
C.
Certificate based Authentication is the only authentication method available between two Security Gateway managed by the same SMS.
D.
The Security Gateways are pre-R75.40.
Answers
D.
The Security Gateways are pre-R75.40.
Suggested answer: C

Explanation:

When two Security Gateways are managed by the same Security Management Server, they use certificate based authentication to establish a VPN tunnel. This is because the Security Management Server acts as an internal certificate authority (ICA) that can issue and revoke certificates for the Security Gateways. The Security Management Server also maintains a trust relationship with the Security Gateways, which is based on a one-time password (OTP) that is used to initialize secure internal communication (SIC). Therefore, there is no need to use a pre-shared secret for authentication between two Security Gateways managed by the same SMS.

asked 16/09/2024
Matteo Zamori
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first