Which address range will be assigned to the AnyConnect users?
Scenario
Your organization has just implemented a Cisco AnyConnect SSL VPN solution. Using Cisco
ASDM, answer the questions regarding the implementation.
Note: Not all screens or option selections are active for this exercise.
Topology
Default_Home
Which address range will be assigned to the AnyConnect users?
What two actions will be taken on translated packets when the AnyConnect users connect to the ASA?
Scenario
Yourorganization has just implemented a Cisco AnyConnect SSL VPN solution. Using Cisco
ASDM, answer the questions regarding the implementation.
Note: Not all screens or option selections are active for this exercise.
Topology
Default_Home
What two actions will be taken on translated packets when the AnyConnect users connect to
the ASA? (Choose two.)
Which two networks will be included in the secured VPN tunnel?
Scenario
Your organization has just implemented a Cisco AnyConnect SSL VPN solution. Using Cisco
ASDM, answer the questions regarding the implementation.
Note: Not all screens or option selections are active for this exercise.
Topology
Default_Home
Which two networks will be included in the secured VPN tunnel? (Choose two.)
Which statement regarding GET VPN is true?
Which statement regarding GET VPN is true?
you need to complete the IPsec connectivity configurations on the HQ ASA…
SIMULATION
ScenarioYou are the network security administrator for your organization. Your company is growing and
a remote branch office is being created. You are tasked with configuring your headquarters
Cisco ASA to create a site-to-site IPsec VPN connection to the branch office Cisco ISR. The
branch office ISR has already been deployed and configured and you need to complete the
IPsec connectivity configurations on the HQ ASA to bring the new office online.
Use the following parameters to complete your configuration using ASDM. For this exercise, not
all ASDM screens are active.
Enable IKEv1 on outside I/F for Site-to-site VPN
Add a Connection Profile with the following parameters:
Peer IP: 203.0.113.1
Connection name: 203.0.113.1
Local protected network: 10.10.9.0/24
Remote protected network: 10.11.11.0/24
Group Policy Name: use the default policy name supplied
Preshared key: cisco
Disable IKEv2
Encryption Algorithms: use the ASA defaults
Disable pre-configured NAT for testing of the IPsec tunnel
Disable the outside NAT pool rule
Establish the IPsec tunnel by sending ICMP pings from the Employee PC to the Branch
Server at IP address 10.11.11.20
Verify tunnel establishment in ASDM VPN Statistics> Sessions window pane
You have completed this exercise when you have successfully configured, established, and
verified site-to-site IPsec connectivity between the ASA and the Branch ISR.
Topology
Which two are features of GETVPN but not DMVPN and FlexVPN?
Which two are features of GETVPN but not DMVPN and FlexVPN? (Choose two.)
Which configuration is used to build a tunnel between a Cisco ASA and ISR?
Which configuration is used to build a tunnel between a Cisco ASA and ISR?
Which two statements regarding IKEv2 are true per RFC 4306?
Which two statements regarding IKEv2 are true per RFC 4306? (Choose two.)
Which three configurations are required for both IPsec VTI and crypto map-based VPNs?
Which three configurations are required for both IPsec VTI and crypto map-based VPNs?
(Choose three.)
Which three parameters must match on all routers in a DMVPN Phase 3 cloud?
Which three parameters must match on all routers in a DMVPN Phase 3 cloud? (Choose three.)