Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A network architect is designing a secure remote access solution for mobile users that need to access internal resources. The solution must support various client operating systems, be easy to configure for end-users, and provide full network layer connectivity. Which VPN technology is best suited for this requirement, leveraging standard web browsers for initial access and then establishing a full tunnel?
- ADMVPN
- BSSL VPN with AnyConnect client
- CIPsec VPN
- DGET VPN
Show answer & explanationAnswer & explanation
Correct answer: B. SSL VPN with AnyConnect client
SSL VPNs, particularly with a client like Cisco AnyConnect, are ideal for remote access. They provide full network layer connectivity, are widely supported across client OS, and often allow initial access via a web browser before deploying the client, making them user-friendly.
Why the other options are wrong
- A. DMVPN is primarily for site-to-site and hub-and-spoke dynamic VPNs, not typically used for individual remote access users.
- C. IPsec VPNs provide full network connectivity but often require more complex client-side configuration and may face NAT traversal issues more frequently than SSL VPNs.
- D. GET VPN (Group Encrypted Transport VPN) is for 'any-to-any' encryption within a group of trusted routers, not for remote access clients.
SSL VPN for Remote Access
A VPN technology that uses the SSL/TLS protocol to create a secure connection between a remote user and an internal network. It is highly flexible, often web-browser friendly, and can provide full network layer access.
- Utilizes standard SSL/TLS ports (e.g., 443), making it firewall-friendly.
- Supports various client types: clientless (web-based), thin client, and full tunnel client (e.g., AnyConnect).
- Ideal for remote access due to ease of deployment and broad OS compatibility.
Memory trick: Remote Users need Secure, Simple, and Standard Access!