PrepAway - Latest Free Exam Questions & Answers

Category: 156-115.77

Exam 156-115.77: Check Point Certified Security Master

What could be the reason?

Tom is troubleshooting NAT issues using fw monitor and Wireshark. He tries to initiate a
connection from the external network to a DMZ server using the public IP which the firewall
translates to the actual IP of the server. He analyzes the captured packets using Wireshark
and observes that the destination IP is being changed as required by the firewall but does
not see the packet leave the external interface. What could be the reason?

Which box in Global Properties should be checked?

Tom has a Web server for which he has created a manual NAT rule. The rule is not
working. He tries to initiate a connection from the external network to a DMZ server using
the public IP which the firewall translates to the actual IP of the server. He analyzes the
captured packets using Wireshark and observes that the destination IP is being changed as
required by the firewall but does not see the packet leave the internal interface. Which box
in Global Properties should be checked?

Does the remote gateway need to include your production gateway’s external IP in its encryption domain?

In a production environment, your gateway is configured to apply a Hide NAT for all internal
traffic destined to the Internet. However, you are setting up a VPN tunnel with a remote
gateway, and you are concerned about the encryption domain that you need to define on
the remote gateway. Does the remote gateway need to include your production gateway’s
external IP in its encryption domain?


Page 5 of 29« First...34567...1020...Last »