300-710 · Question #403
An engineer must configure a remote access VPN on Cisco Secure Firewall Management Center. The engineer created a new remote access VPN policy and updated the access control policy deployed on the…
The correct answer is D. Configure an IP address pool for VPN clients. When configuring a Remote Access VPN (RA-VPN) on Cisco Secure Firewall Management Center (FMC), an IP address pool must be defined to assign IP addresses to connecting VPN clients. Without an address pool, the firewall has no addresses to hand out during IKEv2/SSL negotiation…
Question
An engineer must configure a remote access VPN on Cisco Secure Firewall Management Center. The engineer created a new remote access VPN policy and updated the access control policy deployed on the device. Which additional action must the engineer take to ensure a successful VPN connection?
Options
- ADefine NAT for split tunneling
- BAdd a mandatory NAT exemption
- CPreconfigure a RADIUS/LDAP server
- DConfigure an IP address pool for VPN clients
How the community answered
(43 responses)- A7% (3)
- B2% (1)
- C2% (1)
- D88% (38)
Explanation
When configuring a Remote Access VPN (RA-VPN) on Cisco Secure Firewall Management Center (FMC), an IP address pool must be defined to assign IP addresses to connecting VPN clients. Without an address pool, the firewall has no addresses to hand out during IKEv2/SSL negotiation, and tunnel establishment will fail. Creating the RA-VPN policy and updating the access control policy are necessary steps, but the VPN cannot complete without a pool of client addresses. NAT exemption (Option B) is a common best practice but is not strictly required to establish the VPN itself; the IP pool is the missing mandatory component in this scenario.
Topics
Community Discussion
No community discussion yet for this question.