nerdexam
Cisco

300-730 · Question #28

Which two parameters help to map a VPN session to a tunnel group using the tunnel-group-list? (Choose two.)

The correct answer is B. certificate map D. group-url. On Cisco ASA, group-url and certificate map are the two methods used within a tunnel-group-list to dynamically map an incoming VPN session to a specific tunnel group.

Remote Access VPN

Question

Which two parameters help to map a VPN session to a tunnel group using the tunnel-group-list? (Choose two.)

Options

  • Agroup-alias
  • Bcertificate map
  • Coptimal gateway selection
  • Dgroup-url
  • EAnyConnect client version

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    94% (50)
  • E
    2% (1)

Why each option

On Cisco ASA, group-url and certificate map are the two methods used within a tunnel-group-list to dynamically map an incoming VPN session to a specific tunnel group.

Agroup-alias

A group-alias provides a display name that appears in the AnyConnect login drop-down menu for user convenience, but it is not a mechanism for programmatically mapping a session to a tunnel group via tunnel-group-list.

Bcertificate mapCorrect

A certificate map evaluates attributes in a client's digital certificate - such as CN, OU, or issuer fields - and maps the VPN session to a matching tunnel group, enabling certificate-based tunnel group selection.

Coptimal gateway selection

Optimal gateway selection is an AnyConnect Server List feature that helps clients choose the best ASA based on latency and is entirely unrelated to tunnel group mapping.

Dgroup-urlCorrect

A group-url is a unique URL assigned to a tunnel group; when an AnyConnect or clientless SSL VPN user connects using that specific URL, the ASA automatically maps the session to the corresponding tunnel group.

EAnyConnect client version

The AnyConnect client version is not a configurable criterion for mapping a VPN session to a tunnel group on the ASA.

Concept tested: Cisco ASA tunnel group mapping via group-url and certificate map

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-groups.html

Topics

#tunnel-group-list#certificate map#group-url#VPN session mapping

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice