300-730 · Question #187
What is the role of a tunnel-group configuration of Secure Client remote-access vpn on Cisco ASA?
The correct answer is B. It binds group policy and vpn together.. A tunnel-group (connection profile) on Cisco ASA acts as the binding object that ties together a group policy, authentication method, and VPN connection type for Secure Client remote-access sessions.
Question
Options
- AIt enables clientless webvpn.
- BIt binds group policy and vpn together.
- CIt configures a Secure Client group policy.
- DIt provides an IP address pool.
How the community answered
(52 responses)- A2% (1)
- B92% (48)
- C2% (1)
- D4% (2)
Why each option
A tunnel-group (connection profile) on Cisco ASA acts as the binding object that ties together a group policy, authentication method, and VPN connection type for Secure Client remote-access sessions.
Enabling clientless WebVPN is done through the 'webvpn' configuration block on the ASA interface, not through the tunnel-group.
The tunnel-group configuration on the ASA serves as the connection profile that binds a group policy to VPN connection parameters - it links authentication servers, address assignment, and the associated group policy so the ASA knows which policy to apply when a user connects to that specific tunnel group.
A Secure Client group policy is configured separately using the 'group-policy' command; the tunnel-group references that policy but does not itself define the policy attributes.
IP address pools are defined with the 'ip local pool' command and then assigned within the group-policy or tunnel-group general-attributes, but providing a pool is not the primary defining role of the tunnel-group.
Concept tested: Cisco ASA tunnel-group role in remote-access VPN
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/configuration/vpn/asa-914-vpn-config/vpn-remote-access.html
Topics
Community Discussion
No community discussion yet for this question.