300-730 · Question #139
An engineer has configured Cisco AnyConnect VPN using IKEv2 on a Cisco IOS router. The user cannot connect in the Cisco AnyConnect client, but receives an alert message "Use a browser to gain…
The correct answer is B. Correct the URL address. The 'Use a browser to gain access' message indicates the AnyConnect client is hitting a clientless WebVPN portal URL instead of the correct IKEv2 VPN endpoint URL.
Question
Options
- AReset user login credentials.
- BCorrect the URL address.
- CConnect using HTTPS.
- DDisable the HTTP server.
How the community answered
(52 responses)- A4% (2)
- B71% (37)
- C17% (9)
- D8% (4)
Why each option
The 'Use a browser to gain access' message indicates the AnyConnect client is hitting a clientless WebVPN portal URL instead of the correct IKEv2 VPN endpoint URL.
Resetting user credentials does not address a URL routing issue; the error message is about the connection target, not authentication failure.
When AnyConnect is configured for IKEv2 on a Cisco IOS router, the client must connect to a URL that maps to the IKEv2 VPN profile, not to a clientless SSL VPN portal path. The error message is triggered when the URL in the AnyConnect profile or client points to a WebVPN landing page rather than the correct AnyConnect IKEv2 endpoint. Correcting the URL in the client or XML profile to point to the proper headend address resolves the mismatch.
AnyConnect IKEv2 already uses HTTPS/TLS as its transport; the issue is the destination URL, not the protocol used to connect.
Disabling the HTTP server would break web-based management and redirect functions, and would not fix an incorrect AnyConnect profile URL pointing to the wrong endpoint.
Concept tested: AnyConnect IKEv2 profile URL configuration on IOS
Source: https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/116080-configure-anyconnect-00.html
Topics
Community Discussion
No community discussion yet for this question.