300-730 · Question #28
Which two parameters help to map a VPN session to a tunnel group using the tunnel-group-list? (Choose two.)
The correct answer is B. certificate map D. group-url. On Cisco ASA, group-url and certificate map are the two methods used within a tunnel-group-list to dynamically map an incoming VPN session to a specific tunnel group.
Question
Options
- Agroup-alias
- Bcertificate map
- Coptimal gateway selection
- Dgroup-url
- EAnyConnect client version
How the community answered
(53 responses)- A4% (2)
- B94% (50)
- E2% (1)
Why each option
On Cisco ASA, group-url and certificate map are the two methods used within a tunnel-group-list to dynamically map an incoming VPN session to a specific tunnel group.
A group-alias provides a display name that appears in the AnyConnect login drop-down menu for user convenience, but it is not a mechanism for programmatically mapping a session to a tunnel group via tunnel-group-list.
A certificate map evaluates attributes in a client's digital certificate - such as CN, OU, or issuer fields - and maps the VPN session to a matching tunnel group, enabling certificate-based tunnel group selection.
Optimal gateway selection is an AnyConnect Server List feature that helps clients choose the best ASA based on latency and is entirely unrelated to tunnel group mapping.
A group-url is a unique URL assigned to a tunnel group; when an AnyConnect or clientless SSL VPN user connects using that specific URL, the ASA automatically maps the session to the corresponding tunnel group.
The AnyConnect client version is not a configurable criterion for mapping a VPN session to a tunnel group on the ASA.
Concept tested: Cisco ASA tunnel group mapping via group-url and certificate map
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-groups.html
Topics
Community Discussion
No community discussion yet for this question.