300-730 · Question #50
Which requirement is needed to use local authentication for Cisco AnyConnect Secure Mobility Clients that connect to a FlexVPN server?
The correct answer is D. AnyConnect profile. A local AnyConnect profile must be configured on the FlexVPN server to enable local username/password authentication for AnyConnect clients.
Question
Options
- Ause of certificates instead of username and password
- BEAP-AnyConnect
- CEAP query-identity
- DAnyConnect profile
How the community answered
(25 responses)- A4% (1)
- D96% (24)
Why each option
A local AnyConnect profile must be configured on the FlexVPN server to enable local username/password authentication for AnyConnect clients.
Certificate-based authentication is an alternative method to username/password, not a prerequisite for enabling local credential-based authentication on FlexVPN.
EAP-AnyConnect is one supported EAP method in certain deployments but is not the specific configuration requirement for enabling local authentication on a FlexVPN server.
EAP query-identity is a mechanism for requesting an EAP identity but is not a prerequisite for local authentication on a FlexVPN headend.
An AnyConnect profile is required on the FlexVPN headend to support local AAA authentication for connecting AnyConnect clients. The profile defines client behavior and authentication parameters; without it, the IOS/IOS-XE headend cannot process local credentials submitted by AnyConnect clients during IKEv2 negotiation.
Concept tested: FlexVPN local authentication requirement for AnyConnect clients
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/xe-16/sec-ike2-vpn-xe-16-book/sec-cfg-flex-vpn.html
Topics
Community Discussion
No community discussion yet for this question.