300-730 · Question #190
An engineer configures the Group URL feature on a Cisco Secure Firewall ASA. The requirement is to place contractors using Cisco Secure Client to access the network into a limited access group…
The correct answer is D. group-alias. The Group URL feature on ASA uses the group-alias in the URL path to automatically assign connecting users to a specific tunnel group and its associated group policy.
Question
Exhibit
Options
- Agroup-policy
- Bvpn-filter
- CIP address
- Dgroup-alias
How the community answered
(17 responses)- A12% (2)
- B6% (1)
- C6% (1)
- D76% (13)
Why each option
The Group URL feature on ASA uses the group-alias in the URL path to automatically assign connecting users to a specific tunnel group and its associated group policy.
A group-policy defines VPN attributes applied within a tunnel group but is not directly referenced by name in a Group URL path.
A vpn-filter is an ACL used to restrict traffic for VPN users after they connect and is not referenced in a Group URL.
The IP address identifies the ASA endpoint in the URL hostname, but the specific group identifier used in the URL path to direct users to a tunnel group is the group-alias, not an IP address.
When configuring the Group URL feature, the URL path must reference the group-alias configured on the tunnel group. When a Cisco Secure Client user connects to that URL, the ASA uses the group-alias in the path to identify the correct tunnel group, automatically placing the user into the associated group policy without requiring manual selection. This allows contractors to be seamlessly directed to a limited-access group policy.
Concept tested: ASA Group URL and group-alias for tunnel group selection
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-remote-access.html
Topics
Community Discussion
No community discussion yet for this question.
