300-730 · Question #43
Which feature allows the ASA to handle nonstandard applications and web resources so that they display correctly over a clientless SSL VPN connection?
The correct answer is B. Smart Tunnel. Smart Tunnel allows nonstandard TCP-based applications and web resources to function correctly over Clientless SSL VPN by tunneling traffic directly rather than relying on the ASA content rewriter.
Question
Options
- Asingle sign-on
- BSmart Tunnel
- CWebType ACL
- Dplug-ins
How the community answered
(33 responses)- B94% (31)
- C3% (1)
- D3% (1)
Why each option
Smart Tunnel allows nonstandard TCP-based applications and web resources to function correctly over Clientless SSL VPN by tunneling traffic directly rather than relying on the ASA content rewriter.
Single sign-on enables credential pass-through so users authenticate once across multiple resources, but it does not alter how nonstandard applications or web content are processed or displayed.
Smart Tunnel creates a secure TCP tunnel between the client browser and the private network resource, bypassing the limitations of the ASA content rewriter so that nonstandard applications and web content that fail to render correctly through standard clientless proxying can operate and display properly.
WebType ACLs control which URLs and network resources clientless SSL VPN users are permitted to reach, but they have no effect on how application content is rendered or handled.
Plug-ins are Java-based browser helpers that extend clientless SSL VPN access for specific protocols such as RDP or SSH, but they are not the mechanism used to correct the display of nonstandard web resources.
Concept tested: Smart Tunnel functionality in Clientless SSL VPN
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-clientless.html
Topics
Community Discussion
No community discussion yet for this question.