CCSM Advanced VPN Troubleshooting Practice Question
An administrator configures a Star VPN community between a Check Point R81 gateway and a third-party peer. Phase 1 and Phase 2 complete, but the remote peer reports receiving packets with a source IP that does not match the negotiated selector, causing them to be dropped. The Check Point gateway shows the tunnel as up. Which Check Point mechanism is most likely rewriting the source address before encryption?
⚠ Common exam trap
The trap here is focusing on tunnel establishment state and Link Selection while overlooking NAT rule order, which silently rewrites the inner source before encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hide NAT applied to the internal subnet by a rule above the VPN rule
The remote peer is rejecting inner packets whose source falls outside the negotiated traffic selectors, which points to address translation occurring before encryption. A Hide NAT rule positioned above the VPN rule in the security policy will translate the internal subnet to the gateway address, so the encrypted payload carries an unexpected source and the peer drops it despite a healthy tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Link Selection set to use the gateway's external interface address
Why it's wrong here
Link Selection determines which local address the gateway uses as the IKE and IPsec endpoint, affecting the outer packet headers. It does not alter the inner source address of the encrypted payload, so it cannot explain why the remote peer sees a source outside the selector.
- ✓
Hide NAT applied to the internal subnet by a rule above the VPN rule
Why this is correct
When a Hide NAT rule is evaluated before the VPN encryption rule, the source address is translated to the gateway's external address before entering the VPN path. The remote peer then sees a source that is outside the negotiated encryption domain and discards the packet, even though the tunnel itself is established and healthy.
- ✗
IPsec tunnel management configured for route-based VPN
Why it's wrong here
Route-based VPN changes how traffic is directed into the tunnel using a virtual interface, but it does not modify packet source addresses. The selector mismatch described points to address translation, not to the tunnel interface mode used to route traffic into the VPN.
- ✗
Automatic Static NAT configured on the gateway object
Why it's wrong here
Static NAT on the gateway object maps one address to another but does not typically translate a whole internal subnet to a single external address. Automatic Static NAT also usually aligns with the encryption domain, so it is less likely to produce a source address that contradicts the negotiated selector.
Visual reference
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.