nerdexam
Cisco

300-730 · Question #42

Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)

The correct answer is C. A Cisco ASA can simultaneously allow Clientless SSL VPN sessions and AnyConnect client sessions. D. When a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the ASA uses its configured DNS servers to perform FQDN resolution. Cisco ASA Clientless SSL VPN can simultaneously support both clientless and AnyConnect sessions, and the ASA proxies all client requests using its own configured DNS servers for FQDN resolution.

Remote Access VPN

Question

Which two statements about the Cisco ASA Clientless SSL VPN solution are true? (Choose two.)

Options

  • AWhen a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the client uses the local DNS to perform FQDN resolution.
  • BThe rewriter enable command under the global webvpn configuration enables the rewriter functionality because that feature is disabled by default.
  • CA Cisco ASA can simultaneously allow Clientless SSL VPN sessions and AnyConnect client sessions.
  • DWhen a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the ASA uses its configured DNS servers to perform FQDN resolution.
  • EClientless SSLVPN provides Layer 3 connectivity into the secured network.

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    89% (32)
  • E
    3% (1)

Why each option

Cisco ASA Clientless SSL VPN can simultaneously support both clientless and AnyConnect sessions, and the ASA proxies all client requests using its own configured DNS servers for FQDN resolution.

AWhen a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the client uses the local DNS to perform FQDN resolution.

The client does not use local DNS for FQDN resolution in Clientless SSL VPN because all requests are proxied through the ASA, which handles DNS resolution itself using its configured servers.

BThe rewriter enable command under the global webvpn configuration enables the rewriter functionality because that feature is disabled by default.

The content rewriter is enabled by default in Clientless SSL VPN; there is no 'rewriter enable' command required to activate it under global webvpn configuration.

CA Cisco ASA can simultaneously allow Clientless SSL VPN sessions and AnyConnect client sessions.Correct

The ASA maintains separate session pools for Clientless SSL VPN and AnyConnect SSL VPN, so both connection types can operate concurrently on the same appliance without conflict.

DWhen a client connects to the Cisco ASA WebVPN portal and tries to access HTTP resources through the URL bar, the ASA uses its configured DNS servers to perform FQDN resolution.Correct

In Clientless SSL VPN, the ASA acts as a reverse proxy for all client web requests; when a user enters an FQDN in the WebVPN URL bar, the ASA uses its own configured DNS servers to resolve the name on behalf of the client, not the client's local DNS.

EClientless SSLVPN provides Layer 3 connectivity into the secured network.

Clientless SSL VPN does not provide Layer 3 connectivity - it offers application-layer access to proxied web resources only, unlike AnyConnect which delivers a full Layer 3 IP tunnel.

Concept tested: Cisco ASA Clientless SSL VPN session types and DNS proxying

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-clientless.html

Topics

#clientless SSL VPN#WebVPN#DNS resolution#AnyConnect

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice