Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network architect is designing a secure remote access solution for mobile users that need to access internal resources. The solution must support various client operating systems, be easy to configure for end-users, and provide full network layer connectivity. Which VPN technology is best suited for this requirement, leveraging standard web browsers for initial access and then establishing a full tunnel?

  1. ADMVPN
  2. BSSL VPN with AnyConnect client
  3. CIPsec VPN
  4. DGET VPN
Show answer & explanation

Correct answer: B. SSL VPN with AnyConnect client

SSL VPNs, particularly with a client like Cisco AnyConnect, are ideal for remote access. They provide full network layer connectivity, are widely supported across client OS, and often allow initial access via a web browser before deploying the client, making them user-friendly.

Why the other options are wrong

  • A. DMVPN is primarily for site-to-site and hub-and-spoke dynamic VPNs, not typically used for individual remote access users.
  • C. IPsec VPNs provide full network connectivity but often require more complex client-side configuration and may face NAT traversal issues more frequently than SSL VPNs.
  • D. GET VPN (Group Encrypted Transport VPN) is for 'any-to-any' encryption within a group of trusted routers, not for remote access clients.

SSL VPN for Remote Access

A VPN technology that uses the SSL/TLS protocol to create a secure connection between a remote user and an internal network. It is highly flexible, often web-browser friendly, and can provide full network layer access.

  • Utilizes standard SSL/TLS ports (e.g., 443), making it firewall-friendly.
  • Supports various client types: clientless (web-based), thin client, and full tunnel client (e.g., AnyConnect).
  • Ideal for remote access due to ease of deployment and broad OS compatibility.

Memory trick: Remote Users need Secure, Simple, and Standard Access!

More Security questions