300-730 · Question #213
Refer to the exhibit. An engineer configures Clientless SSL VPN on a Cisco ASA. After the configuration, a user receives this error message in the browser during attempt to connect: Secure Client is…
The correct answer is D. Enable the Clientless VPN protocol for the group policy. The error 'Secure Client is not enabled on the VPN server' appears when the assigned group policy does not have the clientless SSL VPN tunnel protocol explicitly enabled.
Question
Options
- AEnable the AnyConnect Premium license.
- BConfigure a new WebVPN group policy for affected users.
- CConfigure the auto-signon feature from the WebVPN attributes.
- DEnable the Clientless VPN protocol for the group policy.
How the community answered
(52 responses)- A2% (1)
- B4% (2)
- C10% (5)
- D85% (44)
Why each option
The error 'Secure Client is not enabled on the VPN server' appears when the assigned group policy does not have the clientless SSL VPN tunnel protocol explicitly enabled.
The AnyConnect Premium license enables AnyConnect full-tunnel client access, not Clientless SSL VPN, which is a separate feature that does not require this license.
Creating a new group policy does not resolve the issue unless the new policy also explicitly has the clientless VPN tunnel protocol enabled.
The auto-signon feature handles automatic credential submission to internal web applications through the VPN portal and does not control whether users can establish the VPN session itself.
The group policy must permit the clientless VPN protocol via the vpn-tunnel-protocol ssl-clientless command. Without this setting, the ASA rejects the connection attempt even though Clientless SSL VPN is configured globally on the WebVPN gateway. Enabling this protocol in the group policy directly resolves the reported browser error.
Concept tested: Clientless SSL VPN group policy tunnel protocol enablement
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/webvpn-configure-gateway.html
Topics
Community Discussion
No community discussion yet for this question.