Cisco CCNA (200-301)Security FundamentalsHard
A company configures a remote-access VPN for telecommuters using an ASA. Security policy requires that when a VPN client is connected, all of the employee's internet-bound traffic (including personal web browsing) must be routed through the corporate network and inspected, rather than going directly to the internet from the client's local connection. Which VPN tunneling configuration enforces this requirement?
- ASplit tunneling
- BSplit DNS
- CClientless SSL VPN
- DFull tunneling (all traffic forced through the tunnel)
Show answer & explanationAnswer & explanation
Correct answer: D. Full tunneling (all traffic forced through the tunnel)
Full tunneling forces all client traffic, including internet-bound traffic, through the VPN tunnel to the corporate network for inspection and policy enforcement. Split tunneling, in contrast, would allow internet traffic to bypass the tunnel and go directly out the client's local connection, which violates the stated requirement.
Why the other options are wrong
- A. Split tunneling would let personal internet traffic bypass the tunnel, violating the requirement.
- B. Split DNS only affects name resolution behavior, not the routing of traffic itself.
- C. Clientless SSL VPN is a deployment method (browser-based), not related to full vs split tunneling policy.
Full Tunneling vs Split Tunneling
Full tunneling routes all client traffic through the VPN for inspection, while split tunneling only routes traffic destined for corporate resources through the tunnel, letting other traffic go directly to the internet.
- Full tunneling increases security but consumes more bandwidth at the VPN gateway
- Split tunneling improves performance but reduces visibility/control
- Configured via VPN group policy on the ASA or router
Memory trick: Full tunnel = all roads lead through headquarters; split tunnel = some roads go straight to town.