300-730 · Question #208
Refer to the exhibit. A Cisco Adaptive Security Appliance is configured as a Clientless SSL VPN server and uses local user authentication. After a user establishes the Clientless SSL VPN to the…
The correct answer is D. Add port mapping for the new server to the existing port forwarding list. In Clientless SSL VPN, port forwarding lists define which internal TCP-based applications are accessible through the Application Access feature. Adding the new server to the existing list makes it immediately available to all group policies already referencing that list.
Question
Options
- AConfigure identity NAT for the new server.
- BAllow HTTPS traffic to the new server in an access list bound to the outside interface.
- CCreate a new port forwarding list for the new server and enable the list in a group policy.
- DAdd port mapping for the new server to the existing port forwarding list.
How the community answered
(44 responses)- A14% (6)
- B7% (3)
- C2% (1)
- D77% (34)
Why each option
In Clientless SSL VPN, port forwarding lists define which internal TCP-based applications are accessible through the Application Access feature. Adding the new server to the existing list makes it immediately available to all group policies already referencing that list.
Identity NAT is used for address translation exemptions and has no effect on which servers Clientless SSL VPN users can reach through port forwarding.
An access list on the outside interface controls inbound connections to the ASA itself, not the internal resources reachable by already-authenticated Clientless SSL VPN users.
Creating a new port forwarding list would also require updating every relevant group policy to reference the new list, making it unnecessarily complex compared to adding the server to the existing list.
Port forwarding lists in Clientless SSL VPN enumerate the internal servers and TCP ports accessible through the Application Access applet. Adding the new HTTPS server to the existing port forwarding list automatically exposes it to all users whose group policy already references that list, requiring no additional policy reassignment.
Concept tested: Clientless SSL VPN port forwarding list management
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-clientless-ssl.html
Topics
Community Discussion
No community discussion yet for this question.