156-315.81.20 Advanced VPN Design Practice Question
A Check Point security administrator is designing a route-based VPN between two R81.10 Security Gateways. The administrator wants to route dynamic routing protocols (OSPF) and multicast traffic through the VPN tunnel without defining encryption domains for each network. Which VPN community type should be used?
⚠ Common exam trap
The trap here is assuming that any site-to-site VPN community can carry dynamic routing protocols, when only a Route-Based VPN with a VTI supports OSPF and multicast without encryption domains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Route-Based VPN Community
Route-Based VPN communities in Check Point use a virtual tunnel interface (VTI) to route traffic, which allows dynamic routing protocols such as OSPF and multicast to operate over the tunnel. Unlike traditional domain-based VPNs, they do not require encryption domains. The other community types rely on encryption domains or are not designed for site-to-site routing, so they cannot fulfill the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Route-Based VPN Community
Why this is correct
A Route-Based VPN community (also called a VPN tunnel interface or VTI) uses a virtual tunnel interface to route traffic, rather than encryption domains. This allows dynamic routing protocols like OSPF and multicast traffic to traverse the tunnel. It is the correct choice for this scenario because it eliminates the need to define encryption domains for each network and supports advanced routing features.
- ✗
Remote Access VPN Community
Why it's wrong here
Remote Access communities are used for client-to-site connections, typically with Endpoint Security clients or mobile devices. They are not designed for site-to-site route-based tunnels between gateways. Using this community type would not provide the necessary gateway-to-gateway tunnel or support for OSPF and multicast, making it unsuitable for this scenario.
- ✗
Star VPN Community
Why it's wrong here
A Star community is a centralized topology where satellite gateways connect to a central gateway. It still relies on encryption domains to determine which traffic is encrypted, and it is not designed for routing protocols or multicast. Using a Star community here would not meet the requirement to avoid encryption domain definitions and would not support OSPF or multicast over the tunnel.
- ✗
Meshed VPN Community
Why it's wrong here
A Meshed community allows direct communication between all gateways, but it also uses encryption domains to select traffic for encryption. It does not inherently support dynamic routing protocols or multicast without additional configuration. The requirement to route OSPF and multicast without defining encryption domains points to a different community type, not a Meshed one.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.