300-730 · Question #31
Refer to the exhibit. Which value must be configured in the User Group field when the Cisco AnyConnect profile is created to connect to an ASA headend with IPsec as the primary protocol?
The correct answer is D. tunnel-group. When configuring an AnyConnect profile to use IPsec as the primary protocol to an ASA headend, the User Group field must contain the tunnel-group name, not a display alias or URL.
Question
Options
- Aaddress-pool
- Bgroup-alias
- Cgroup-url
- Dtunnel-group
How the community answered
(67 responses)- A6% (4)
- B1% (1)
- C4% (3)
- D88% (59)
Why each option
When configuring an AnyConnect profile to use IPsec as the primary protocol to an ASA headend, the User Group field must contain the tunnel-group name, not a display alias or URL.
address-pool defines the IP address range assigned to VPN clients and is not a group identifier used during connection profile selection.
group-alias is a display name that appears in the AnyConnect drop-down menu for SSL VPN connections; it is not used for IPsec IKEv2 group matching.
group-url is an SSL-specific mechanism that maps a URL path to a connection profile and is not applicable when IPsec is the primary protocol.
IPsec IKEv2 uses the tunnel-group name as the identity selector during the IKE negotiation phase to map the client to the correct connection profile on the ASA. The AnyConnect profile's 'User Group' field must exactly match the tunnel-group name configured on the ASA headend so the correct policy, authentication, and authorization settings are applied.
Concept tested: AnyConnect IPsec IKEv2 User Group to tunnel-group mapping
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-anyconnect.html
Topics
Community Discussion
No community discussion yet for this question.