nerdexam
Cisco

300-730 · Question #208

Refer to the exhibit. A Cisco Adaptive Security Appliance is configured as a Clientless SSL VPN server and uses local user authentication. After a user establishes the Clientless SSL VPN to the…

The correct answer is D. Add port mapping for the new server to the existing port forwarding list. In Clientless SSL VPN, port forwarding lists define which internal TCP-based applications are accessible through the Application Access feature. Adding the new server to the existing list makes it immediately available to all group policies already referencing that list.

Remote Access VPN

Question

Refer to the exhibit. A Cisco Adaptive Security Appliance is configured as a Clientless SSL VPN server and uses local user authentication. After a user establishes the Clientless SSL VPN to the Cisco Adaptive Security Appliance, the user can reach an existing internal secure web server by using the Application Access settings. Which configuration must be made on the Cisco Adaptive Security Appliance to allow the Clientless SSL VPN users to access new secure web servers that are added to the internal network?

Options

  • AConfigure identity NAT for the new server.
  • BAllow HTTPS traffic to the new server in an access list bound to the outside interface.
  • CCreate a new port forwarding list for the new server and enable the list in a group policy.
  • DAdd port mapping for the new server to the existing port forwarding list.

How the community answered

(44 responses)
  • A
    14% (6)
  • B
    7% (3)
  • C
    2% (1)
  • D
    77% (34)

Why each option

In Clientless SSL VPN, port forwarding lists define which internal TCP-based applications are accessible through the Application Access feature. Adding the new server to the existing list makes it immediately available to all group policies already referencing that list.

AConfigure identity NAT for the new server.

Identity NAT is used for address translation exemptions and has no effect on which servers Clientless SSL VPN users can reach through port forwarding.

BAllow HTTPS traffic to the new server in an access list bound to the outside interface.

An access list on the outside interface controls inbound connections to the ASA itself, not the internal resources reachable by already-authenticated Clientless SSL VPN users.

CCreate a new port forwarding list for the new server and enable the list in a group policy.

Creating a new port forwarding list would also require updating every relevant group policy to reference the new list, making it unnecessarily complex compared to adding the server to the existing list.

DAdd port mapping for the new server to the existing port forwarding list.Correct

Port forwarding lists in Clientless SSL VPN enumerate the internal servers and TCP ports accessible through the Application Access applet. Adding the new HTTPS server to the existing port forwarding list automatically exposes it to all users whose group policy already references that list, requiring no additional policy reassignment.

Concept tested: Clientless SSL VPN port forwarding list management

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-clientless-ssl.html

Topics

#Clientless SSL VPN#port forwarding#web server access#group policy

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice