Courseiva

CCSM Advanced VPN Troubleshooting Practice Question

An administrator configures a Star VPN community between a Check Point R81 gateway and a third-party peer. Phase 1 and Phase 2 complete, but the remote peer reports receiving packets with a source IP that does not match the negotiated selector, causing them to be dropped. The Check Point gateway shows the tunnel as up. Which Check Point mechanism is most likely rewriting the source address before encryption?

⚠ Common exam trap

The trap here is focusing on tunnel establishment state and Link Selection while overlooking NAT rule order, which silently rewrites the inner source before encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hide NAT applied to the internal subnet by a rule above the VPN rule

The remote peer is rejecting inner packets whose source falls outside the negotiated traffic selectors, which points to address translation occurring before encryption. A Hide NAT rule positioned above the VPN rule in the security policy will translate the internal subnet to the gateway address, so the encrypted payload carries an unexpected source and the peer drops it despite a healthy tunnel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Link Selection set to use the gateway's external interface address

    Why it's wrong here

    Link Selection determines which local address the gateway uses as the IKE and IPsec endpoint, affecting the outer packet headers. It does not alter the inner source address of the encrypted payload, so it cannot explain why the remote peer sees a source outside the selector.

  • ✓

    Hide NAT applied to the internal subnet by a rule above the VPN rule

    Why this is correct

    When a Hide NAT rule is evaluated before the VPN encryption rule, the source address is translated to the gateway's external address before entering the VPN path. The remote peer then sees a source that is outside the negotiated encryption domain and discards the packet, even though the tunnel itself is established and healthy.

  • ✗

    IPsec tunnel management configured for route-based VPN

    Why it's wrong here

    Route-based VPN changes how traffic is directed into the tunnel using a virtual interface, but it does not modify packet source addresses. The selector mismatch described points to address translation, not to the tunnel interface mode used to route traffic into the VPN.

  • ✗

    Automatic Static NAT configured on the gateway object

    Why it's wrong here

    Static NAT on the gateway object maps one address to another but does not typically translate a whole internal subnet to a single external address. Automatic Static NAT also usually aligns with the encryption domain, so it is less likely to produce a source address that contradicts the negotiated selector.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.