Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A network security engineer is designing a secure remote access solution for a global organization. The solution needs to support a wide range of client devices (Windows, macOS, Linux, mobile) and provide full network access to corporate resources without requiring a dedicated client application on every device. The solution must also be easily deployable and managed. Which VPN technology is best suited for these requirements?
- AGRE over IPsec
- BIPsec VPN with AnyConnect client
- CDMVPN
- DSSL VPN (clientless)
Show answer & explanationAnswer & explanation
Correct answer: D. SSL VPN (clientless)
SSL VPN (clientless) is ideal for providing remote access to common corporate resources (web applications, file shares) without requiring a dedicated client application. It uses a standard web browser, making it highly compatible across various operating systems and devices, and is easy to deploy.
Why the other options are wrong
- A. GRE over IPsec is primarily a site-to-site VPN technology, not designed for remote access from individual clients.
- B. IPsec VPN with AnyConnect client requires a specific client application to be installed on each device.
- C. DMVPN is a site-to-site technology for dynamic hub-and-spoke or spoke-to-spoke connections, not for individual remote users.
SSL VPN (Clientless)
A type of Virtual Private Network that provides secure remote access to internal network resources using a standard web browser, eliminating the need for dedicated client software.
- Uses SSL/TLS for encryption, typically over port 443.
- Access is provided via a web portal, often to web applications, file shares, or terminal services.
- Highly compatible with various operating systems and devices due to browser-based access.
- Simpler to deploy and manage for basic remote access needs compared to client-based VPNs.
Memory trick: Remote Access: Client, Browser, or Site-to-Site?