Soru

Zorluk: KolayRemote Access and Site-to-Site VPN Concepts

An enterprise network administrator needs to securely connect a fixed branch office network to the corporate headquarters over the public Internet. The connection must operate transparently to end users and encrypt all traffic between the two network gateways without requiring software installation on individual host computers. Which VPN deployment model and technology best satisfies this requirement?

  1. Site-to-Site IPsec VPNCevap
  2. B
    Remote Access SSL VPN
  3. C
    Remote Access IPsec VPN using Cisco AnyConnect
  4. D
    Clientless SSL VPN via web browser portal

Cevap

Site-to-Site IPsec VPN
A Site-to-Site IPsec VPN is specifically engineered to securely connect two static locations across an untrusted public network. Gateway devices (such as Cisco ISR routers or ASA/FTD firewalls) handle all encryption and decryption at the network boundary, allowing end hosts on both subnets to communicate seamlessly without requiring local client software.

Adım Adım Çözüm

1
Identify the topology requirement from the scenario
The requirement calls for interconnecting two fixed site locations (branch office and corporate headquarters) using infrastructure devices.
Differentiating between site-to-site connectivity and individual user connectivity determines whether a Site-to-Site or Remote Access VPN model is needed.
2
Evaluate host software dependencies and transparency requirements
A Site-to-Site IPsec VPN uses routers or firewalls as dedicated tunnel endpoints to encrypt and decrypt network traffic transparently, requiring zero configuration or software on end-user hosts.
Remote Access solutions (both SSL and IPsec host-based models) rely on individual endpoint software or user sessions.

Anahtar Kavram

Site-to-Site vs Remote Access VPN Topology Characteristics
Bu soruyu puanla