Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityHard

A network administrator is troubleshooting an issue where users are unable to access internal web applications despite having an active SSL VPN connection through a Cisco ASA. The administrator suspects a misconfiguration related to the traffic that should be encapsulated within the VPN tunnel. Which configuration element on the ASA defines which traffic should be sent through the SSL VPN tunnel and which traffic should be sent unencrypted over the physical interface?

  1. ASplit Tunneling List
  2. BConnection Profile (Tunnel Group)
  3. CGroup Policy
  4. DDynamic Access Policy (DAP)
Show answer & explanation

Correct answer: A. Split Tunneling List

The Split Tunneling List (configured within a Group Policy, but a distinct element) is specifically responsible for defining which traffic (based on destination networks) will traverse the SSL VPN tunnel (encrypted) and which traffic will go directly to the internet (unencrypted). If internal web applications are not included in this list (or if split tunneling is disabled and full tunnel is not enforced), they won't be reachable through the VPN.

Why the other options are wrong

  • B. A Connection Profile (Tunnel Group) defines authentication, IP address assignment, and references to group policies, but it doesn't directly specify the networks for split tunneling.
  • C. Group Policy is a container for various settings, including split tunneling, but the 'Split Tunneling List' is the specific element within it that controls the traffic flow.
  • D. DAP defines authorization attributes (e.g., access lists, VLANs) based on endpoint posture but doesn't directly control split tunneling traffic flow.

SSL VPN Split Tunneling List

A configuration element, typically an Access Control List (ACL) or network list, used in SSL VPNs (like Cisco AnyConnect) to define which traffic should be sent through the encrypted VPN tunnel (for internal resources) and which traffic should be sent directly to the public internet (unencrypted).

  • Controls whether all traffic or only specific traffic goes through the VPN.
  • Improves performance for non-corporate traffic.
  • Can be a security risk if not carefully configured, allowing untunneled access to the internet while connected to the VPN.

Memory trick: Split Tunneling decides the traffic's path: Tunnel or Not!

More Security questions