An enterprise requires remote employees using corporate laptops to establish a secure network-layer tunnel back to the headquarters firewall. The solution must support all IP-based applications and operate seamlessly across restrictive public networks by encapsulating traffic inside TLS or DTLS on port 443. Which VPN technology should the administrator deploy to satisfy these requirements?
- SSL/TLS remote access VPN utilizing a dedicated software clientCevap
- BClientless SSL VPN accessed exclusively through a web browser portal
- CIPsec site-to-site VPN operating in transport mode between endpoints
- DGeneric Routing Encapsulation (GRE) tunnel configured directly on client operating systems
Cevap
SSL/TLS remote access VPN utilizing a dedicated software client
Client-based SSL/TLS remote access VPNs (such as Cisco Secure Client / AnyConnect) create a virtual network interface on the user's endpoint, encapsulating all network-layer IP traffic inside TLS (TCP 443) or DTLS (UDP 443). This satisfies both requirements: supporting arbitrary IP applications and seamlessly bypassing restrictive firewalls.
Adım Adım Çözüm
Anahtar Kavram
SSL/TLS Remote Access VPN Client-Based Architecture vs Clientless and Site-to-Site VPNs
Tahmini Süre:1m 15s