nerdexam
Cisco

300-730 · Question #31

Refer to the exhibit. Which value must be configured in the User Group field when the Cisco AnyConnect profile is created to connect to an ASA headend with IPsec as the primary protocol?

The correct answer is D. tunnel-group. When configuring an AnyConnect profile to use IPsec as the primary protocol to an ASA headend, the User Group field must contain the tunnel-group name, not a display alias or URL.

Remote Access VPN

Question

Refer to the exhibit. Which value must be configured in the User Group field when the Cisco AnyConnect profile is created to connect to an ASA headend with IPsec as the primary protocol?

Options

  • Aaddress-pool
  • Bgroup-alias
  • Cgroup-url
  • Dtunnel-group

How the community answered

(67 responses)
  • A
    6% (4)
  • B
    1% (1)
  • C
    4% (3)
  • D
    88% (59)

Why each option

When configuring an AnyConnect profile to use IPsec as the primary protocol to an ASA headend, the User Group field must contain the tunnel-group name, not a display alias or URL.

Aaddress-pool

address-pool defines the IP address range assigned to VPN clients and is not a group identifier used during connection profile selection.

Bgroup-alias

group-alias is a display name that appears in the AnyConnect drop-down menu for SSL VPN connections; it is not used for IPsec IKEv2 group matching.

Cgroup-url

group-url is an SSL-specific mechanism that maps a URL path to a connection profile and is not applicable when IPsec is the primary protocol.

Dtunnel-groupCorrect

IPsec IKEv2 uses the tunnel-group name as the identity selector during the IKE negotiation phase to map the client to the correct connection profile on the ASA. The AnyConnect profile's 'User Group' field must exactly match the tunnel-group name configured on the ASA headend so the correct policy, authentication, and authorization settings are applied.

Concept tested: AnyConnect IPsec IKEv2 User Group to tunnel-group mapping

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-anyconnect.html

Topics

#AnyConnect profile#tunnel-group#IPsec primary protocol#ASA headend

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice