300-730 · Question #52
Refer to the exhibit. Which VPN technology is allowed for users connecting to the Employee tunnel group?
The correct answer is D. clientless. The Employee tunnel-group configuration shown in the exhibit permits only clientless SSL VPN, restricting browser-based access without a full VPN client.
Question
Options
- ASSL AnyConnect
- BIKEv2 AnyConnect
- Ccrypto map
- Dclientless
How the community answered
(19 responses)- A5% (1)
- B5% (1)
- C11% (2)
- D79% (15)
Why each option
The Employee tunnel-group configuration shown in the exhibit permits only clientless SSL VPN, restricting browser-based access without a full VPN client.
SSL AnyConnect requires the AnyConnect image and client download to be enabled within the tunnel-group webvpn-attributes, which is absent in the exhibit's Employee group configuration.
IKEv2 AnyConnect requires IKEv2 to be explicitly enabled on the tunnel-group along with an AnyConnect profile, neither of which is present in the shown configuration.
Crypto map-based VPN is used for site-to-site IPsec tunnels and is not applicable to remote access webvpn tunnel-group configurations.
The exhibit's tunnel-group webvpn-attributes configuration for the Employee group enables only clientless mode, which provides browser-based access to internal web resources. No AnyConnect client download is enabled and no IKEv2 VPN type is configured for this tunnel group, making clientless the only permitted VPN technology.
Concept tested: ASA tunnel-group VPN access type restriction via webvpn-attributes
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-groups.html
Topics
Community Discussion
No community discussion yet for this question.