nerdexam
Cisco

300-730 · Question #11

Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?

The correct answer is A. IKEv2 authorization policy. On a Cisco IOS router, IKEv2 remote access split tunneling is defined inside the IKEv2 authorization policy, which pushes route and traffic-selector attributes to connecting clients.

Remote Access VPN

Question

Where is split tunneling defined for IKEv2 remote access clients on a Cisco router?

Options

  • AIKEv2 authorization policy
  • BGroup Policy
  • Cvirtual template
  • Dwebvpn context

How the community answered

(60 responses)
  • A
    78% (47)
  • B
    3% (2)
  • C
    12% (7)
  • D
    7% (4)

Why each option

On a Cisco IOS router, IKEv2 remote access split tunneling is defined inside the IKEv2 authorization policy, which pushes route and traffic-selector attributes to connecting clients.

AIKEv2 authorization policyCorrect

The IKEv2 authorization policy on a Cisco IOS router is the construct that specifies client-pushed attributes including route sets, which directly control split tunneling behavior by telling the client which prefixes to send through the tunnel versus the local internet. These attributes are delivered to the remote access client during IKEv2 negotiation via the Config payload. This is the IOS router equivalent of the ASA group policy split-tunneling configuration.

BGroup Policy

Group Policy is a configuration object used on Cisco ASA and FTD platforms, not on IOS router IKEv2 remote access deployments.

Cvirtual template

Virtual templates define logical interface properties and cloning behavior for tunnel interfaces but do not carry client-pushed attributes such as split tunneling route lists.

Dwebvpn context

The webvpn context is specific to SSL VPN and WebVPN configuration on Cisco devices and has no role in IKEv2 remote access client attribute delivery.

Concept tested: IKEv2 authorization policy split tunneling on IOS

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ikevpn/configuration/xe-16/sec-conn-ikevpn-xe-16-book/sec-conn-ikev2-flex.html

Topics

#IKEv2#split tunneling#authorization policy#FlexVPN remote access

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice