300-730 · Question #51
Which IKE identity does an IOS/IOS-XE headend expect to receive if an IPsec Cisco AnyConnect client uses default settings?
The correct answer is B. *$AnyConnectClient$*. AnyConnect clients using default IPsec/IKEv2 settings send $AnyConnectClient$ as their IKE identity to the IOS/IOS-XE headend.
Question
Options
- A$SecureMobilityClient$
- B$AnyConnectClient$
- C$RemoteAccessVpnClient$
- D$DfltIkeIdentityS
How the community answered
(35 responses)- B94% (33)
- C3% (1)
- D3% (1)
Why each option
AnyConnect clients using default IPsec/IKEv2 settings send *$AnyConnectClient$* as their IKE identity to the IOS/IOS-XE headend.
*$SecureMobilityClient$* is not the default IKE identity string sent by AnyConnect clients and would not match the headend's expected identity for default configurations.
By default, Cisco AnyConnect clients present the IKE identity string *$AnyConnectClient$* during IKEv2 negotiation. The IOS/IOS-XE headend uses this identity to recognize connecting AnyConnect clients and apply the correct authorization policy and tunnel-group configuration.
*$RemoteAccessVpnClient$* is not a valid AnyConnect default IKE identity string and would cause IKEv2 peer identification to fail.
*$DfltIkeIdentityS* does not correspond to any standard AnyConnect client default and is not a recognized identity string for AnyConnect IKEv2 sessions.
Concept tested: Default IKE identity string for AnyConnect IPsec IKEv2 clients
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-anyconnect.html
Topics
Community Discussion
No community discussion yet for this question.