300-730 · Question #72
An engineer is configuring clientless SSL VPN. The finance department has a database server that only they should access, but the sales department can currently access it. The finance and the sales…
The correct answer is D. webtype ACL. Webtype ACLs are the purpose-built mechanism in clientless SSL VPN for restricting access to URLs and server resources on a per-group-policy basis.
Question
Options
- Atunnel group lock
- Bsmart tunnel
- Cport forwarding
- Dwebtype ACL
How the community answered
(45 responses)- A18% (8)
- B2% (1)
- C9% (4)
- D71% (32)
Why each option
Webtype ACLs are the purpose-built mechanism in clientless SSL VPN for restricting access to URLs and server resources on a per-group-policy basis.
Tunnel group lock restricts users to a specific tunnel group connection profile and controls which VPN policy they bind to at login, not which servers they can reach after connecting.
Smart tunnel enables specific thick-client applications to run over the clientless SSL VPN session but does not provide access restriction between different group policies.
Port forwarding enables specific TCP application access for clientless VPN users but is an enablement feature, not a mechanism to restrict access between group policies.
Webtype ACLs are specifically designed for clientless SSL VPN and filter access to URLs, TCP/UDP ports, and network resources for users in a given group-policy. By applying a webtype ACL to the sales group-policy that denies access to the finance database server's address or URL, sales users are blocked from reaching it even though they can authenticate to the VPN. This is the correct and purpose-built feature for cross-department resource restriction in clientless VPN.
Concept tested: Clientless SSL VPN webtype ACL group-policy access restriction
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/webvpn-config.html
Topics
Community Discussion
No community discussion yet for this question.