300-730 · Question #133
Over the weekend, an administrator upgraded the Cisco ASA image on the firewalls and noticed that users cannot connect to the headquarters site using Cisco AnyConnect. What is the solution for this is
The correct answer is A. Upgrade the Cisco AnyConnect client version to be compatible with the Cisco ASA software image.. When a Cisco ASA is upgraded to a new software version, the AnyConnect client on endpoints must also be upgraded to a compatible version to restore VPN connectivity.
Question
Options
- AUpgrade the Cisco AnyConnect client version to be compatible with the Cisco ASA software image.
- BUpgrade the Cisco AnyConnect Network Access module to be compatible with the Cisco ASA software image.
- CUpgrade the Cisco AnyConnect client driver to be compatible with the Cisco ASA software image.
- DUpgrade the Cisco AnyConnect Start Before Logon module to be compatible with the Cisco ASA software image.
How the community answered
(42 responses)- A88% (37)
- B2% (1)
- C7% (3)
- D2% (1)
Why each option
When a Cisco ASA is upgraded to a new software version, the AnyConnect client on endpoints must also be upgraded to a compatible version to restore VPN connectivity.
Cisco ASA and AnyConnect client versions have a compatibility matrix that ties specific client versions to supported headend software releases. After an ASA upgrade, the headend may enforce a minimum client version and reject connections from outdated clients. Upgrading the AnyConnect client to a version validated against the new ASA image resolves the connection failure.
The Network Access Manager is an optional AnyConnect module for 802.1X network authentication and is not responsible for the core SSL or IPsec VPN tunnel establishment used to connect to the ASA.
'Client driver' is not a recognized component in the Cisco AnyConnect architecture - the correct upgrade target is the AnyConnect Secure Mobility Client application itself.
The Start Before Logon module is an optional feature that enables a VPN connection before the Windows logon screen, and its version does not affect post-logon VPN connectivity to the ASA headend.
Concept tested: AnyConnect and ASA software version compatibility
Source: https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200533-AnyConnect-Supported-OSes-and-Browsers.html
Topics
Community Discussion
No community discussion yet for this question.