nerdexam
Cisco

300-710 · Question #403

An engineer must configure a remote access VPN on Cisco Secure Firewall Management Center. The engineer created a new remote access VPN policy and updated the access control policy deployed on the…

The correct answer is D. Configure an IP address pool for VPN clients. When configuring a Remote Access VPN (RA-VPN) on Cisco Secure Firewall Management Center (FMC), an IP address pool must be defined to assign IP addresses to connecting VPN clients. Without an address pool, the firewall has no addresses to hand out during IKEv2/SSL negotiation…

Configuration

Question

An engineer must configure a remote access VPN on Cisco Secure Firewall Management Center. The engineer created a new remote access VPN policy and updated the access control policy deployed on the device. Which additional action must the engineer take to ensure a successful VPN connection?

Options

  • ADefine NAT for split tunneling
  • BAdd a mandatory NAT exemption
  • CPreconfigure a RADIUS/LDAP server
  • DConfigure an IP address pool for VPN clients

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    88% (38)

Explanation

When configuring a Remote Access VPN (RA-VPN) on Cisco Secure Firewall Management Center (FMC), an IP address pool must be defined to assign IP addresses to connecting VPN clients. Without an address pool, the firewall has no addresses to hand out during IKEv2/SSL negotiation, and tunnel establishment will fail. Creating the RA-VPN policy and updating the access control policy are necessary steps, but the VPN cannot complete without a pool of client addresses. NAT exemption (Option B) is a common best practice but is not strictly required to establish the VPN itself; the IP pool is the missing mandatory component in this scenario.

Topics

#Remote Access VPN#Cisco Secure Firewall#FMC#VPN Client IP Pool

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice