Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium
A security engineer is designing a secure remote access solution for mobile users. The solution must support various operating systems, provide strong authentication, and ensure that all traffic to the corporate network is encrypted. Which VPN technology, when implemented with certificate-based authentication, provides the most flexible and robust solution for this scenario?
- ARemote access SSL VPN
- BSite-to-site IPsec VPN
- CGRE over IPsec VPN
- DL2TP over IPsec VPN
Show answer & explanationAnswer & explanation
Correct answer: A. Remote access SSL VPN
Remote access SSL VPNs (like Cisco AnyConnect) are highly flexible, widely supported across various operating systems, and use the ubiquitous SSL/TLS protocol, which typically traverses firewalls easily. When combined with certificate-based authentication, it provides strong security for mobile users.
Why the other options are wrong
- B. Site-to-site IPsec is for connecting networks, not individual remote users.
- C. GRE over IPsec is typically used for site-to-site or specific routing scenarios, not directly for individual remote user access.
- D. L2TP over IPsec is a valid remote access option but SSL VPNs often offer greater flexibility, especially in diverse network environments and with easier firewall traversal for mobile users.
Remote Access SSL VPN
A type of Virtual Private Network (VPN) that uses the Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocol to create a secure, encrypted connection for individual remote users to access a private network.
- Designed for 'client-to-site' connections.
- Widely supported by web browsers and dedicated clients (e.g., Cisco AnyConnect).
- Uses TCP port 443, making it firewall-friendly.
- Offers strong encryption and authentication options (e.g., certificates, MFA).
Memory trick: For mobile access, SSL is the universal key and shield.