CCSM Advanced VPN Troubleshooting Practice Question
An administrator is troubleshooting an IPsec VPN that intermittently drops large file transfers while small pings succeed. The gateways are Check Point Security Gateways running R81.20. Which TWO actions should the administrator take to identify and resolve the issue? (Choose two.)
⚠ Common exam trap
The trap here is assuming intermittent VPN drops are negotiation or authentication failures, when the size-dependent pattern points to MTU and fragmentation issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check whether the IPsec packet size exceeds the path MTU and enable MSS clamping or adjust the MTU on the external interface.
Intermittent drops during large transfers while small pings succeed point to an MTU or fragmentation problem. Checking whether IPsec packets exceed the path MTU and applying MSS clamping or MTU adjustments reduces packet size, while verifying DF bit handling and allowing ICMP type 3 code 4 ensures Path MTU Discovery works. Together these actions identify and resolve the size-dependent packet loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run 'vpn debug ikeon' and analyze ike.elg for Phase 1 and Phase 2 negotiation errors.
Why it's wrong here
IKE debugging captures key exchange negotiations, which are relevant when tunnels fail to establish or rekey. In this scenario the tunnel is already up and small pings succeed, so the intermittent drops are data-plane issues rather than negotiation failures. Analyzing ike.elg would not reveal MTU or fragmentation problems and would consume time without addressing the symptom.
- ✗
Disable NAT-Traversal on both gateways to eliminate UDP encapsulation overhead.
Why it's wrong here
NAT-Traversal is required when peers are behind NAT devices, and disabling it can break the tunnel entirely. While NAT-T adds a small UDP header, it is not the cause of size-dependent drops. Disabling it would not resolve the MTU issue and could introduce new connectivity failures. The administrator should instead address packet size and ICMP handling, which directly affect large transfers.
- ✗
Reset the user's certificate and require re-enrollment to refresh the IKE credentials.
Why it's wrong here
Certificate issues would prevent authentication and tunnel establishment, not cause intermittent drops only for large packets. Since the tunnel is established and small pings succeed, credentials are working correctly. Resetting certificates would disrupt a functioning VPN without addressing the size-dependent packet loss, which is characteristic of an MTU or fragmentation problem rather than an authentication problem.
- ✓
Check whether the IPsec packet size exceeds the path MTU and enable MSS clamping or adjust the MTU on the external interface.
Why this is correct
Large file transfers produce full-size packets that can exceed the path MTU when IPsec overhead is added, causing fragmentation or drops that do not affect small pings. Checking the effective MTU and applying MSS clamping or lowering the interface MTU reduces packet size so they traverse the VPN without fragmentation, resolving the intermittent failure for bulk traffic while preserving small-packet connectivity.
- ✓
Verify that the DF bit is not being cleared incorrectly and confirm that ICMP type 3 code 4 messages are permitted through the path.
Why this is correct
Path MTU Discovery relies on ICMP fragmentation-needed messages, and if these are blocked, the sender never learns to reduce packet size, causing large packets to be dropped. Confirming that the DF bit handling is correct and that ICMP type 3 code 4 is allowed ensures PMTUD can function. This directly addresses intermittent failures for large transfers while small pings remain unaffected.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.