ETExamTower
Q21Remote access VPNs

Where is split tunneling configured for IKEv2 remote-access clients on a Cisco router?

← → navigate · a answer
Community votes
A
100% (4)
B
0% (0)
C
0% (0)
D
0% (0)
Discussion · 14
3
I'd say A - IKEv2 Authorization Policy Source (Step 13): https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.html Webvpn is for SSL remote access VPN's and the question asks about an IKEv2 remote access
A 3
Selected Answer: A Step 13 (Optional). By default, all client traffic is sent through the tunnel. You can set up split tunneling, which lets only selected traffic go through the tunnel. ip access-list standard split_tunnel permit 10.0.0.0 0.255.255.255 ! crypto ikev2 authorization policy ikev2-auth-policy route set access-list split_tunnel https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.html#toc-hId-936641904
2
for IKEv2 A is correct like Lantis wrote if it where IKEv1 group policy would be right https://www.cisco.com/c/en/us/support/docs/routers/3600-series-multiservice-platforms/91193-rtr-ipsec-internet-connect.html
2
Naa, Group policy if I am correct is on ASA
1
WebVPN context -> group-> svc->split D is correct
1
Im gonna go with group policy on this one. Step 13 (Optional). By default, all traffic from the client will be sent through the tunnel. You can configure split tunnel, which allows only selected traffic to go through the tunnel. ip access-list standard split_tunnel permit 10.0.0.0 0.255.255.255 ! crypto ikev2 authorization policy ikev2-auth-policy route set access-list split_tunnel https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.html
1
Correction. Authorization Policy not group policy
A 1
Selected Answer: A Defined in IKEv2 auth policy
A 1
Selected Answer: A A is correct
1
a big A
1
Group policy sounds right here.
1
A is the correct answer
1
On a Cisco router, split tunneling for IKEv2 remote access clients is usually defined in the Group Policy configuration. The Group Policy sets different parameters and settings for a specific group of remote access clients. Inside the Group Policy configuration, you can choose whether split tunneling should be turned on or off for the IKEv2 remote access clients tied to that group. Split tunneling decides how network traffic is routed when a remote access client connects to the router using IKEv2. It lets the client choose which traffic goes through the VPN tunnel and which traffic is sent directly to the local network or the internet. While IKEv2 Authorization Policy can also affect access permissions and policies for IKEv2 remote access clients, split tunneling itself is generally configured in the Group Policy. So, the correct answer is that split tunneling for IKEv2 remote access clients on a Cisco router is defined in the Group Policy.
1
Answer should be A https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.html