156-215.81.20 VPN Basics Practice Question
An administrator is configuring a Site-to-Site VPN between two Check Point R81 Security Gateways using a Star community. The administrator wants to ensure that the VPN tunnel is established and that traffic is encrypted and decrypted correctly. Which two actions must be performed on both gateways to allow the VPN to function properly? (Choose two.)
⚠ Common exam trap
The trap here is assuming that NAT or community topology changes are necessary for VPN establishment, when in fact the core requirements are the VPN domain and authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a pre-shared secret or certificate for authentication in the VPN community.
For a Site-to-Site VPN to establish and pass traffic, both gateways must have a correctly defined VPN domain that includes the networks to be encrypted, and they must share matching authentication credentials (pre-shared secret or certificates). These are fundamental requirements for IKE Phase 1 and Phase 2 to succeed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Accept all encrypted traffic' in the Global Properties.
Why it's wrong here
This option is not a standard requirement for Site-to-Site VPN. Global Properties settings like 'Accept all encrypted traffic' are typically used for debugging or specific scenarios, not for basic VPN establishment. Enabling it unnecessarily could weaken security by accepting encrypted traffic from any source.
- ✓
Define a pre-shared secret or certificate for authentication in the VPN community.
Why this is correct
Authentication is essential for IKE Phase 1. Both gateways must have matching authentication credentials, either a pre-shared secret or certificates, configured in the VPN community. Without correct authentication, the VPN tunnel cannot be established, and Phase 1 will fail.
- ✗
Set the VPN community to 'Meshed' instead of 'Star'.
Why it's wrong here
The community topology (Star vs. Meshed) determines the communication flow between gateways. Changing to Meshed would not address the fundamental requirements for VPN establishment; both topologies require correct VPN domain and authentication. This change is not necessary and could complicate the configuration.
- ✗
Configure NAT rules to hide the internal networks behind the gateway's external IP address.
Why it's wrong here
NAT rules are not required for VPN functionality and can actually interfere with VPN traffic if not properly exempted. In many Site-to-Site VPNs, NAT is disabled or bypassed for VPN traffic. Configuring NAT would not help establish the tunnel and could cause encryption domain mismatches.
- ✓
Configure the VPN domain to include the internal networks that should be encrypted.
Why this is correct
The VPN domain defines which IP addresses are considered internal and are encrypted when communicating over the VPN. It must be correctly configured on both gateways to include the subnets that need protection. If the VPN domain is missing or incorrect, traffic will not be encrypted or may be dropped.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.