Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A network architect is designing a secure remote access solution for employees who need to connect to the corporate network from various locations using their personal devices. The solution must support full network layer access to internal resources, enforce strong authentication, and be highly scalable. Which VPN technology is best suited for this scenario, allowing clients to establish a secure tunnel to the corporate network?
- AGRE Tunnel
- BSSL VPN (Clientless)
- CAnyConnect SSL VPN
- DSite-to-Site IPsec VPN
Show answer & explanationAnswer & explanation
Correct answer: C. AnyConnect SSL VPN
AnyConnect SSL VPN (often referred to as Client-based SSL VPN) provides full network layer access (Layer 3) to corporate resources, enforces strong authentication, and is highly scalable for remote users, making it ideal for this scenario. It requires a client application.
Why the other options are wrong
- A. GRE tunnels provide encapsulation but no inherent encryption or strong authentication for remote access.
- B. Clientless SSL VPN provides limited web-browser access, not full network layer access.
- D. Site-to-Site IPsec VPN connects networks, not individual remote users.
Cisco AnyConnect SSL VPN
A client-based SSL VPN solution that provides full Layer 3 network access for remote users to an enterprise network.
- Requires a client application on the end-user device.
- Uses SSL/TLS for secure communication.
- Offers granular access control and strong authentication.
Memory trick: Remote workers need a secure 'Any' path to 'Connect' to the office.