350-701 · Question #730
An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generated by the user is sent…
The correct answer is D. group policy. To exclude specific server traffic from a Cisco AnyConnect VPN tunnel and allow direct access, the group policy on the Cisco Secure Firewall must be modified to implement split tunneling.
Question
An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generated by the user is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goal?
Options
- ANAT exemption
- Bencryption domain
- Crouting table
- Dgroup policy
How the community answered
(24 responses)- A13% (3)
- B8% (2)
- C4% (1)
- D75% (18)
Why each option
To exclude specific server traffic from a Cisco AnyConnect VPN tunnel and allow direct access, the group policy on the Cisco Secure Firewall must be modified to implement split tunneling.
NAT exemption prevents NAT from occurring for traffic within the VPN, but it does not control whether traffic is initially directed into or out of the VPN tunnel.
The encryption domain defines which traffic is encrypted by the VPN, but for AnyConnect, the more granular control over what client-initiated traffic enters the tunnel is managed through split tunneling within the group policy.
While the client's routing table is updated by the VPN connection, the administrative control to modify these client-side routing directives for specific traffic exclusions resides within the firewall's group policy configuration.
In a Cisco AnyConnect VPN deployment, split tunneling behavior, which dictates what traffic goes through the VPN tunnel versus what traffic accesses the local network directly, is configured within the group policy on the Cisco Secure Firewall. Modifying the group policy's split tunneling network list will achieve the goal of excluding specific servers.
Concept tested: Cisco AnyConnect split tunneling configuration
Source: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118314-configure-asa-anyconnect-00.html
Topics
Community Discussion
No community discussion yet for this question.