An enterprise needs to grant external consultants secure access to web-based internal applications from their personal, unmanaged laptops. The security policy strictly forbids requiring local administrative rights or installing persistent client software on the end-user endpoints. Which VPN deployment model best satisfies these operational constraints?
- Clientless SSL/TLS VPN accessed through a native web browserAnswer
- BSite-to-site IPsec VPN operating in Tunnel Mode between boundary routers
- CRemote access IPsec VPN using full-tunnel client software
- DIPsec VPN with Generic Routing Encapsulation (GRE) in transport mode
Answer
Clientless SSL/TLS VPN accessed through a native web browser
Clientless SSL/TLS VPN allows users to securely connect to web-based internal network resources using only a standard web browser. Because the browser handles the SSL/TLS session, no administrative privileges or specialized client applications are required on the host device.
Step-by-Step Solution
Key Concept
Clientless SSL VPN vs Client-based Remote Access VPN Architecture