Check Point recommends deploying SSL VPN:
A.
In parallel to the firewall
B.
In a DMZ
C.
In front of the firewall with a LAN connection
D.
On the Primary cluster member
Check Point recommends deploying SSL VPN:
Check Point recommends deploying SSL VPN:
A.
In parallel to the firewall
B.
In a DMZ
C.
In front of the firewall with a LAN connection
D.
On the Primary cluster member
… Generally Check Point recommends that Connectra (it is a SSL VPN Gateway) be deployed in the DMZ, but LAN deployment is also an option…
http://www.checkpoint.com/services/education/training/courses/samples/connectra_ngx_sample.pdf
http://downloads.us.checkpoint.com/fileserver/SOURCE/direct/ID/10322/FILE/CP_R71_SSLVPN_AdminGuide.pdf
Correct answer is B
The correct answer is “C”. Page 14 of the admin guide for R75
Recommended Deployments
Mobile Access can be deployed in a variety of ways depending on an organization’s system architecture and preferences.
http://dl3.checkpoint.com/paid/57/CP_R75_MobileAccess_AdminGuide.pdf?HashKey=1390785907_ff0a3e23598ed53fffc1e2fb571ed442&xtn=.pdf
So we mast stick to R71 admin guide – deployed in the DMZ
Answer “B”
Security best practice, use “B” for the answer.
Correct Answer must be “C” as it is clearly mentioned in SSL VPN Admin Guide as ‘Recommended deployment’ on Page 12. Whereas DMZ is NOT specifically mentioned as a recommended deployment though it is one of the type of deployments.