300-730 · Question #90
An administrator is setting up AnyConnect for the first time for a few users. Currently, the router does not have access to a RADIUS server. Which AnyConnect protocol must be used to allow users to…
The correct answer is D. EAP-AnyConnect. When no RADIUS server is available, EAP-AnyConnect is the only AnyConnect EAP type that authenticates users against a local database on the headend device.
Question
Options
- AEAP-GTC
- BEAP-MSCHAPv2
- CEAP-MD5
- DEAP-AnyConnect
How the community answered
(54 responses)- A6% (3)
- B2% (1)
- C4% (2)
- D89% (48)
Why each option
When no RADIUS server is available, EAP-AnyConnect is the only AnyConnect EAP type that authenticates users against a local database on the headend device.
EAP-GTC requires an external authentication server such as RADIUS to validate one-time passwords or token-based credentials.
EAP-MSCHAPv2 depends on a RADIUS server or Active Directory to perform the MS-CHAP challenge-response exchange.
EAP-MD5 requires a RADIUS server to store and verify the MD5-hashed user credentials.
EAP-AnyConnect is Cisco's proprietary EAP method that allows the AnyConnect headend router or ASA to authenticate users using its local user database, eliminating the requirement for an external RADIUS server. It is the only EAP type in the AnyConnect framework that fully supports local authentication without external infrastructure. This makes it the correct choice when no RADIUS server is accessible.
Concept tested: AnyConnect EAP local authentication without RADIUS
Source: https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect49/administration/guide/b_AnyConnect_Administrator_Guide_4-9.html
Topics
Community Discussion
No community discussion yet for this question.