156-215.81.20 VPN Basics Practice Question
A security administrator is troubleshooting a Site-to-Site VPN between two Check Point R81 gateways. The VPN tunnel is up, but traffic from a specific subnet behind Gateway A is not reaching the corresponding subnet behind Gateway B. The administrator has verified that the encryption domains include the correct subnets and that the VPN community is properly configured. Which action should the administrator take next to resolve the issue?
⚠ Common exam trap
The trap here is assuming that a successful VPN tunnel establishment automatically allows all traffic, overlooking the need for explicit policy rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the Security Policy on both gateways allows the traffic between the subnets.
When a VPN tunnel is established but traffic fails to pass, the most common cause is a missing or misconfigured Security Policy rule on one or both gateways. The policy must explicitly allow the traffic between the subnets. Other settings like NAT, tunnel granularity, or permanent tunnels do not control whether traffic is permitted through the tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the 'Tunnel Granularity' in the VPN community to 'Per Subnet Pair'.
Why it's wrong here
Tunnel Granularity determines how many IPsec tunnels are created between gateways. Changing it from 'Per Gateway Pair' to 'Per Subnet Pair' increases the number of tunnels but does not affect whether traffic is allowed by the security policy. This setting is useful for optimizing traffic flows but will not resolve a policy-related block.
- ✓
Verify that the Security Policy on both gateways allows the traffic between the subnets.
Why this is correct
Even if the VPN tunnel is established, the Security Policy on each gateway must explicitly allow traffic between the involved subnets. If the policy blocks the traffic, it will not be encrypted and forwarded. This is a common oversight when encryption domains are correct but the rulebase lacks a permissive rule for the specific subnets.
- ✗
Check the 'Disable NAT inside the VPN Community' setting in the VPN community.
Why it's wrong here
While NAT can interfere with VPN traffic, the symptom described is that traffic is not reaching the remote subnet at all. If NAT were the issue, traffic might be dropped or misrouted, but the first step is to ensure the security policy permits the traffic. The 'Disable NAT inside the VPN Community' setting is relevant only if NAT is applied to VPN traffic, which is not indicated here.
- ✗
Enable 'Permanent Tunnels' in the VPN community to keep the tunnel active.
Why it's wrong here
Permanent Tunnels ensure that the VPN tunnel remains established even when there is no traffic. However, the tunnel is already up in this scenario, so enabling Permanent Tunnels would not address the issue of traffic not reaching the remote subnet. The problem is likely due to a missing or incorrect security policy rule.
Visual reference
About these practice questions
Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.