An enterprise network administrator needs to securely connect a fixed branch office network to the corporate headquarters over the public Internet. The connection must operate transparently to end users and encrypt all traffic between the two network gateways without requiring software installation on individual host computers. Which VPN deployment model and technology best satisfies this requirement?
- Site-to-Site IPsec VPNAnswer
- BRemote Access SSL VPN
- CRemote Access IPsec VPN using Cisco AnyConnect
- DClientless SSL VPN via web browser portal
Answer
Site-to-Site IPsec VPN
A Site-to-Site IPsec VPN is specifically engineered to securely connect two static locations across an untrusted public network. Gateway devices (such as Cisco ISR routers or ASA/FTD firewalls) handle all encryption and decryption at the network boundary, allowing end hosts on both subnets to communicate seamlessly without requiring local client software.
Step-by-Step Solution
Key Concept
Site-to-Site vs Remote Access VPN Topology Characteristics