300-730 · Question #42
Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)
The correct answer is C. A Cisco ASA can simultaneously allow Clientless SSL VPN sessions and AnyConnect client sessions. D. When a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the ASA uses its configured DNS servers to perform FQDN resolution. Cisco ASA Clientless SSL VPN can simultaneously support both clientless and AnyConnect sessions, and the ASA proxies all client requests using its own configured DNS servers for FQDN resolution.
Question
Options
- AWhen a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the client uses the local DNS to perform FQDN resolution.
- BThe rewriter enable command under the global webvpn configuration enables the rewriter functionality because that feature is disabled by default.
- CA Cisco ASA can simultaneously allow Clientless SSL VPN sessions and AnyConnect client sessions.
- DWhen a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the ASA uses its configured DNS servers to perform FQDN resolution.
- EClientless SSLVPN provides Layer 3 connectivity into the secured network.
How the community answered
(36 responses)- A6% (2)
- B3% (1)
- C89% (32)
- E3% (1)
Why each option
Cisco ASA Clientless SSL VPN can simultaneously support both clientless and AnyConnect sessions, and the ASA proxies all client requests using its own configured DNS servers for FQDN resolution.
The client does not use local DNS for FQDN resolution in Clientless SSL VPN because all requests are proxied through the ASA, which handles DNS resolution itself using its configured servers.
The content rewriter is enabled by default in Clientless SSL VPN; there is no 'rewriter enable' command required to activate it under global webvpn configuration.
The ASA maintains separate session pools for Clientless SSL VPN and AnyConnect SSL VPN, so both connection types can operate concurrently on the same appliance without conflict.
In Clientless SSL VPN, the ASA acts as a reverse proxy for all client web requests; when a user enters an FQDN in the WebVPN URL bar, the ASA uses its own configured DNS servers to resolve the name on behalf of the client, not the client's local DNS.
Clientless SSL VPN does not provide Layer 3 connectivity - it offers application-layer access to proxied web resources only, unlike AnyConnect which delivers a full Layer 3 IP tunnel.
Concept tested: Cisco ASA Clientless SSL VPN session types and DNS proxying
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-clientless.html
Topics
Community Discussion
No community discussion yet for this question.