300-730 · Question #38
Which two features provide headend resiliency for Cisco AnyConnect clients? (Choose two.)
The correct answer is C. AnyConnect Backup Servers D. ASA failover. Headend resiliency for AnyConnect ensures clients can reach an alternate ASA if the primary becomes unavailable.
Question
Options
- AAnyConnect Auto Reconnect
- BAnyConnect Network Access Manager
- CAnyConnect Backup Servers
- DASA failover
- EAnyConnect Always On
How the community answered
(42 responses)- B5% (2)
- C93% (39)
- E2% (1)
Why each option
Headend resiliency for AnyConnect ensures clients can reach an alternate ASA if the primary becomes unavailable.
Auto Reconnect re-establishes a dropped session to the same headend but does not redirect the client to a different ASA.
Network Access Manager manages wired and wireless 802.1X authentication and is entirely unrelated to VPN headend availability.
AnyConnect Backup Servers defines an ordered list of alternate headend ASAs in the VPN client profile. If the primary ASA is unreachable, the client automatically attempts each backup server in sequence, providing transparent failover without requiring user intervention.
ASA failover configures a secondary ASA to take over if the primary device fails hardware or software checks. Active/standby or active/active failover keeps the headend continuously available so existing sessions are preserved and new connections can still be established.
Always On enforces continuous VPN connectivity by preventing users from bypassing the tunnel, but does not define alternate headend addresses for failover.
Concept tested: AnyConnect headend resiliency mechanisms
Source: https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect46/administration/guide/b_AnyConnect_Administrator_Guide_4-6/configure-vpn.html
Topics
Community Discussion
No community discussion yet for this question.