ExamGecko
Question list
Search
Search

Related questions











Question 159 - 300-730 discussion

Report
Export

A network engineer must configure the Cisco ASA so that Cisco AnyConnect clients establishing an SSL VPN connection create an additional tunnel for real-time traffic that is sensitive to packet delays. If this additional tunnel experiences any issues, it must fall back to a TLS connection. Which two Cisco AnyConnect features must be configured to accomplish this task? (Choose two.)

A.

DTLS

Answers
A.

DTLS

B.

DSCP Preservation

Answers
B.

DSCP Preservation

C.

DPD

Answers
C.

DPD

D.

SSL Rekey

Answers
D.

SSL Rekey

E.

OMTU

Answers
E.

OMTU

Suggested answer: A, C

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-anyconnect.html

Configure Dead Peer Detection Dead Peer Detection (DPD) ensures that the ASA (gateway) or the client can quickly detect a condition where the peer is not responding, and the connection has failed. To enable dead peer detection (DPD) and set the frequency with which either the AnyConnect client or the ASA gateway performs DPD, do the following: Before you begin This feature applies to connectivity between the ASA gateway and the AnyConnect SSL VPN Client only. It does not work with IPsec since DPD is based on the standards implementation that does not allow padding, and CLientless SSL VPN is not supported. If you enable DTLS, enable Dead Peer Detection (DPD) also. DPD enables a failed DTLS connection to fallback to TLS. Otherwise, the connection terminates.

asked 10/10/2024
Okan YILDIZ
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first