CCSM Advanced VPN Troubleshooting Practice Question
An administrator notices that a site-to-site VPN tunnel between two Check Point gateways intermittently drops and re-establishes. The logs show 'IKE Phase 2 rekey failed' followed by 'Tunnel deleted'. What is the most likely cause?
⚠ Common exam trap
The trap here is focusing on PFS or shared secret issues when the symptom specifically points to rekeying, which is governed by lifetime settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IKE phase 2 lifetime differs between the two gateways.
Intermittent tunnel drops with rekey failures often result from mismatched Phase 2 lifetimes. When one peer initiates rekeying before the other's lifetime expires, the other peer may reject the new proposal. Ensuring both gateways use the same Phase 2 lifetime resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPN community is configured with Perfect Forward Secrecy disabled.
Why it's wrong here
Disabling PFS is a valid configuration and does not cause rekey failures by itself. Rekey failures typically stem from parameter mismatches or connectivity issues during the rekey process. If PFS were the issue, it would have prevented the initial tunnel establishment, not just the rekey.
- ✓
The IKE phase 2 lifetime differs between the two gateways.
Why this is correct
If the Phase 2 lifetime values are not identical, the gateway with the shorter lifetime will initiate a rekey before the other is ready, leading to proposal mismatches and rekey failures. Aligning the Phase 2 lifetime on both peers ensures synchronized rekeying and prevents tunnel drops.
- ✗
The shared secret is configured with special characters that are not supported.
Why it's wrong here
Special characters in the shared secret are generally supported and would cause an initial Phase 1 failure if problematic, not an intermittent rekey failure. The tunnel established successfully at first, so the shared secret is valid; the issue arises during rekey, pointing to lifetime or proposal mismatches.
- ✗
The VPN tunnel is using UDP port 500 instead of UDP port 4500.
Why it's wrong here
Port 500 is used for IKE when no NAT-T is required; port 4500 is used only when NAT is detected. Using port 500 is not inherently wrong and would not cause rekey failures. The intermittent nature suggests a configuration mismatch rather than a port issue.
Visual reference
About these practice questions
This CCSM question is part of Courseiva's 219-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.