nerdexam
Cisco

300-730 · Question #213

Refer to the exhibit. An engineer configures Clientless SSL VPN on a Cisco ASA. After the configuration, a user receives this error message in the browser during attempt to connect: Secure Client is…

The correct answer is D. Enable the Clientless VPN protocol for the group policy. The error 'Secure Client is not enabled on the VPN server' appears when the assigned group policy does not have the clientless SSL VPN tunnel protocol explicitly enabled.

Troubleshooting VPNs

Question

Refer to the exhibit. An engineer configures Clientless SSL VPN on a Cisco ASA. After the configuration, a user receives this error message in the browser during attempt to connect: Secure Client is not enabled on the VPN server. Which action must the engineer take to resolve the issue?

Options

  • AEnable the AnyConnect Premium license.
  • BConfigure a new WebVPN group policy for affected users.
  • CConfigure the auto-signon feature from the WebVPN attributes.
  • DEnable the Clientless VPN protocol for the group policy.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    10% (5)
  • D
    85% (44)

Why each option

The error 'Secure Client is not enabled on the VPN server' appears when the assigned group policy does not have the clientless SSL VPN tunnel protocol explicitly enabled.

AEnable the AnyConnect Premium license.

The AnyConnect Premium license enables AnyConnect full-tunnel client access, not Clientless SSL VPN, which is a separate feature that does not require this license.

BConfigure a new WebVPN group policy for affected users.

Creating a new group policy does not resolve the issue unless the new policy also explicitly has the clientless VPN tunnel protocol enabled.

CConfigure the auto-signon feature from the WebVPN attributes.

The auto-signon feature handles automatic credential submission to internal web applications through the VPN portal and does not control whether users can establish the VPN session itself.

DEnable the Clientless VPN protocol for the group policy.Correct

The group policy must permit the clientless VPN protocol via the vpn-tunnel-protocol ssl-clientless command. Without this setting, the ASA rejects the connection attempt even though Clientless SSL VPN is configured globally on the WebVPN gateway. Enabling this protocol in the group policy directly resolves the reported browser error.

Concept tested: Clientless SSL VPN group policy tunnel protocol enablement

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/webvpn-configure-gateway.html

Topics

#Clientless SSL VPN#group policy#VPN protocol#WebVPN

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice