300-730 · Question #11
Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?
The correct answer is A. IKEv2 authorization policy. On a Cisco IOS router, IKEv2 remote access split tunneling is defined inside the IKEv2 authorization policy, which pushes route and traffic-selector attributes to connecting clients.
Question
Options
- AIKEv2 authorization policy
- BGroup Policy
- Cvirtual template
- Dwebvpn context
How the community answered
(60 responses)- A78% (47)
- B3% (2)
- C12% (7)
- D7% (4)
Why each option
On a Cisco IOS router, IKEv2 remote access split tunneling is defined inside the IKEv2 authorization policy, which pushes route and traffic-selector attributes to connecting clients.
The IKEv2 authorization policy on a Cisco IOS router is the construct that specifies client-pushed attributes including route sets, which directly control split tunneling behavior by telling the client which prefixes to send through the tunnel versus the local internet. These attributes are delivered to the remote access client during IKEv2 negotiation via the Config payload. This is the IOS router equivalent of the ASA group policy split-tunneling configuration.
Group Policy is a configuration object used on Cisco ASA and FTD platforms, not on IOS router IKEv2 remote access deployments.
Virtual templates define logical interface properties and cloning behavior for tunnel interfaces but do not carry client-pushed attributes such as split tunneling route lists.
The webvpn context is specific to SSL VPN and WebVPN configuration on Cisco devices and has no role in IKEv2 remote access client attribute delivery.
Concept tested: IKEv2 authorization policy split tunneling on IOS
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ikevpn/configuration/xe-16/sec-conn-ikevpn-xe-16-book/sec-conn-ikev2-flex.html
Topics
Community Discussion
No community discussion yet for this question.