Courseiva
Advanced VPN Design →mediumMultiple Choice

156-315.81.20 Advanced VPN Design Practice Question

A Check Point security administrator is designing a route-based VPN between two R81.10 Security Gateways. The administrator wants to route dynamic routing protocols (OSPF) and multicast traffic through the VPN tunnel without defining encryption domains for each network. Which VPN community type should be used?

⚠ Common exam trap

The trap here is assuming that any site-to-site VPN community can carry dynamic routing protocols, when only a Route-Based VPN with a VTI supports OSPF and multicast without encryption domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Route-Based VPN Community

Route-Based VPN communities in Check Point use a virtual tunnel interface (VTI) to route traffic, which allows dynamic routing protocols such as OSPF and multicast to operate over the tunnel. Unlike traditional domain-based VPNs, they do not require encryption domains. The other community types rely on encryption domains or are not designed for site-to-site routing, so they cannot fulfill the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Route-Based VPN Community

    Why this is correct

    A Route-Based VPN community (also called a VPN tunnel interface or VTI) uses a virtual tunnel interface to route traffic, rather than encryption domains. This allows dynamic routing protocols like OSPF and multicast traffic to traverse the tunnel. It is the correct choice for this scenario because it eliminates the need to define encryption domains for each network and supports advanced routing features.

  • ✗

    Remote Access VPN Community

    Why it's wrong here

    Remote Access communities are used for client-to-site connections, typically with Endpoint Security clients or mobile devices. They are not designed for site-to-site route-based tunnels between gateways. Using this community type would not provide the necessary gateway-to-gateway tunnel or support for OSPF and multicast, making it unsuitable for this scenario.

  • ✗

    Star VPN Community

    Why it's wrong here

    A Star community is a centralized topology where satellite gateways connect to a central gateway. It still relies on encryption domains to determine which traffic is encrypted, and it is not designed for routing protocols or multicast. Using a Star community here would not meet the requirement to avoid encryption domain definitions and would not support OSPF or multicast over the tunnel.

  • ✗

    Meshed VPN Community

    Why it's wrong here

    A Meshed community allows direct communication between all gateways, but it also uses encryption domains to select traffic for encryption. It does not inherently support dynamic routing protocols or multicast without additional configuration. The requirement to route OSPF and multicast without defining encryption domains points to a different community type, not a Meshed one.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.