Courseiva
Advanced VPN Design →mediumMultiple Choice

156-315.81.20 Advanced VPN Design Practice Question

A Check Point administrator is configuring a Site-to-Site VPN between a Security Gateway and a third-party device using IKEv2. The third-party device requires a specific non-standard IKEv2 proposal. Where should the administrator define this custom proposal in SmartConsole?

⚠ Common exam trap

Candidates often look for custom IKE settings in the VPN Community object. While logical, Check Point requires these specific non-standard IKEv2 proposals to be configured within the Gateway object's advanced settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Under the Gateway object > IPsec VPN > Advanced > IKEv2 Proposals.

Custom IKEv2 proposals are defined within the VPN Advanced settings of the Gateway object. While standard proposals are pre-defined, interoperability with third-party vendors often necessitates manual negotiation settings. Defining these correctly is critical for successful Phase 1 establishment, as mismatches in encryption, integrity, or Diffie-Hellman groups will result in IKE negotiation failures, preventing the tunnel from initiating securely between the disparate security appliances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In the Global Properties under VPN Advanced settings.

    Why it's wrong here

    Global Properties define enterprise-wide behavior for all gateways, but specific IKEv2 proposal customization for a single third-party peer is not managed here. This location handles general VPN settings like IKE Phase 1/2 lifetimes and NAT-Traversal, but lacks the granular object-specific proposal control required for individual site-to-site connectivity.

  • ✗

    Within the VPN Community object properties.

    Why it's wrong here

    VPN Communities manage the encryption domains and shared secrets for tunnels, but they do not house the specific IKEv2 proposal negotiation parameters. These parameters must be defined at the gateway level to ensure the specific cryptographic suite is supported before the community tunnel negotiation even begins.

  • ✓

    Under the Gateway object > IPsec VPN > Advanced > IKEv2 Proposals.

    Why this is correct

    The Gateway object contains the specific IPsec VPN advanced settings where custom IKEv2 proposals are configured. By manually defining the encryption and integrity algorithms here, the administrator ensures the gateway proposes settings compatible with the third-party device, facilitating successful IKE Phase 1 negotiation during the initial tunnel setup.

  • ✗

    In the Policy tab under the VPN Rule properties.

    Why it's wrong here

    The VPN rule in the Access Control policy defines which traffic is permitted through the tunnel, not how the tunnel is negotiated. Configuring proposals here is not possible because the rule only validates the connection once the IKE/IPsec tunnels have been successfully established by the gateway's daemon processes.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.