N10-005 · Question #736
An administrator has set up several IPSec and SSL tunnels to terminate on a single device. Which of the following has the administrator deployed?
The correct answer is C. VPN Concentrator. A VPN concentrator is a dedicated device designed to terminate and manage a large number of simultaneous VPN tunnels, including both IPSec and SSL types.
Question
An administrator has set up several IPSec and SSL tunnels to terminate on a single device. Which of the following has the administrator deployed?
Options
- AProxy Server
- BLoad Balancer
- CVPN Concentrator
- DWeb-Application Firewall
How the community answered
(35 responses)- A3% (1)
- B3% (1)
- C89% (31)
- D6% (2)
Why each option
A VPN concentrator is a dedicated device designed to terminate and manage a large number of simultaneous VPN tunnels, including both IPSec and SSL types.
A proxy server acts as an intermediary for client web requests to retrieve content on their behalf and does not terminate VPN tunnels.
A load balancer distributes incoming network traffic or application requests across multiple backend servers to improve availability and does not manage VPN tunnel termination.
A VPN concentrator aggregates multiple incoming VPN tunnels - whether IPSec site-to-site tunnels or SSL/TLS remote-access tunnels - onto a single appliance, handling encryption, authentication, and tunnel management at scale. It is purpose-built for this function, offering high throughput and many concurrent session support beyond what a general-purpose router or firewall provides. Cisco ASA and similar appliances are common examples deployed as VPN concentrators.
A Web Application Firewall (WAF) inspects and filters HTTP/HTTPS traffic to protect web applications from attacks such as SQL injection and XSS, and is not designed to terminate IPSec or SSL VPN tunnels.
Concept tested: VPN concentrator for multi-tunnel IPSec and SSL termination
Source: https://www.cisco.com/c/en/us/products/security/vpn-concentrators/index.html
Topics
Community Discussion
No community discussion yet for this question.