ETExamTower
Q15Remote access VPNs

A network engineer needs to deploy an SSLVPN Cisco AnyConnect solution that supports 500 concurrent users, ensures that all client traffic traverses the ASA, and permits users to reach every device on the inside-interface subnet (192.168.0.0/24). Assuming all other configuration is appropriately configured, which configuration implements this solution?

Question exhibitQuestion exhibitQuestion exhibitQuestion exhibit
← → navigate · a answer
Discussion · 7
11
First, tunnel all to make sure all traffic is going through the ASA (so answer is A or D). Second, we need 500 users, so the pool in D does not meet that requirement (only 254 IPs), so answer is A
7
A is right. Tunnel All for all traffic through the FW. And the /22 pool supports 500 and more users.
5
"ensures all traffic from the client passes through the ASA" that's one of the requirements. That means all traffic should go through the tunnel, I know they mention 192.168.0.0 network but that is just to confuse. Correct Answer is A
2
Users need to access all devices on the subnet 192.168.0.0/24. So the correct answer should be B, because tunnel all policy will allow access to everything and not only the internal subnet of 192.168.0.0
1
please explain
1
I would go with "A" too, since "all traffic" includes 192.168.0.0/24
1
in this case, it should have been exclude specified