156-315.81.20 Advanced VPN Design Practice Question
A Check Point administrator is troubleshooting a Site-to-Site VPN where the tunnel is up, but traffic is not passing. The administrator runs 'vpn tu tlist' and sees the tunnel is established. However, 'fw monitor' shows packets being dropped with the error 'Encryption failure: no SA'. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming a routing or PSK issue, when the tunnel is up and the error specifically points to an encryption domain mismatch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The encryption domain of the local gateway does not include the source or destination network of the dropped packets.
The error 'Encryption failure: no SA' occurs when a packet matches a VPN rule but the gateway cannot find an existing SA for that traffic. This usually happens when the packet's source or destination is not included in the VPN encryption domain, so the gateway cannot map it to the established tunnel. The administrator should check the VPN Domain settings on both gateways to ensure they include all relevant networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Security Gateway's routing table is missing a route to the remote network.
Why it's wrong here
A missing route would cause the packet to be dropped with a routing error, not an encryption failure. The 'no SA' error specifically indicates that the gateway cannot find a matching SA for encryption, which points to encryption domain mismatch.
- ✗
The pre-shared key is incorrect.
Why it's wrong here
An incorrect pre-shared key would prevent Phase 1 from completing, so the tunnel would not be up. Since 'vpn tu tlist' shows the tunnel is established, the PSK is correct. The issue is specific to certain traffic, not the tunnel itself.
- ✓
The encryption domain of the local gateway does not include the source or destination network of the dropped packets.
Why this is correct
The error 'Encryption failure: no SA' means the gateway attempted to encrypt a packet but found no matching SA for that traffic. This typically occurs when the packet's source or destination is not within the VPN's encryption domain, so the gateway cannot associate it with an existing tunnel. The administrator should verify the VPN Domain configuration on both gateways.
- ✗
The VPN community is not configured to allow the specific traffic.
Why it's wrong here
If the VPN community did not allow the traffic, the packets would be dropped by policy with a 'No valid SA' or 'Encryption failure: policy' error, not 'no SA'. The error 'no SA' indicates a missing Security Association for that particular traffic, often due to a mismatch in encryption domains.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.