300-730 · Question #82
Which Cisco AnyConnect component ensures that devices in a specific internal subnet are only accessible using port 443?
The correct answer is D. VPN filter. A VPN filter is an ACL applied to AnyConnect VPN sessions that restricts traffic by IP, protocol, and port, making it the correct mechanism to limit access to an internal subnet on port 443 only.
Question
Options
- Arouting
- BWebACL
- Csplit tunnel
- DVPN filter
How the community answered
(19 responses)- A5% (1)
- B5% (1)
- D89% (17)
Why each option
A VPN filter is an ACL applied to AnyConnect VPN sessions that restricts traffic by IP, protocol, and port, making it the correct mechanism to limit access to an internal subnet on port 443 only.
Routing determines the forwarding path for traffic but provides no mechanism to enforce port-level restrictions on which traffic may reach a subnet.
WebACL is not a standard Cisco AnyConnect component used to restrict VPN session traffic by port or protocol.
Split tunneling divides traffic between the corporate VPN tunnel and the local internet but does not enforce port-based access control to specific internal subnets.
A VPN filter is an ACL that the ASA applies directly to a VPN session, enabling granular control over which protocols and ports are permitted to reach internal resources. It can be configured to permit only TCP port 443 traffic destined for the specified internal subnet, enforcing port-based access restrictions on VPN-connected users. This is distinct from general routing or group policy and is the only AnyConnect component designed for per-session traffic filtering at the port level.
Concept tested: Cisco AnyConnect VPN filter port-based access control
Source: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/214390-configure-vpn-filter-on-asa.html
Topics
Community Discussion
No community discussion yet for this question.