Soru

Zorluk: OrtaVirtual Private Networks and Remote Access Security

Match each secure remote access protocol or configuration feature on the left with its corresponding primary technical capability on the right.

  • IKEv2Maintains active VPN tunnel connections during network switching (such as transitioning from Wi-Fi to cellular data).
  • Clientless SSL/TLS VPNProvides secure remote access to web-based applications over TCP port 443 without requiring endpoint software installation.
  • Split TunnelingRoutes corporate-bound traffic through the VPN while sending public Internet traffic directly out the local gateway.
  • RADIUSProvides centralized authentication, authorization, and accounting for remote access clients over UDP ports 1812 and 1813.

Cevap

IKEv2 matches seamless VPN session persistence across network changes; Clientless SSL/TLS VPN matches browser-based access on TCP port 443 without local software; Split Tunneling matches selective encryption for corporate subnets while permitting direct local Internet access; RADIUS matches centralized remote access AAA services using UDP ports 1812 and 1813.
Each technology is accurately paired with its primary security or functional role: IKEv2 handles seamless client mobility and network interface switching, Clientless SSL/TLS provides clientless browser portal access over TCP port 443, Split Tunneling manages traffic path routing to conserve perimeter resources, and RADIUS provides centralized AAA authentication across UDP 1812/1813.

Adım Adım Çözüm

1
Evaluate mobility requirements for client VPN connections.
Identify IKEv2 as the IPsec key exchange protocol engineered with MOBIKE capabilities to sustain sessions when mobile devices change IP addresses.
Standard IPsec tunnels drop during IP re-assignment, whereas IKEv2 dynamically updates tunnel endpoints.
2
Determine deployment requirements for browser-based remote access.
Associate Clientless SSL/TLS VPN with HTML5 web portal access operating on standard TCP port 443.
Allows secure web portal proxying without deploying endpoint software or requiring elevated OS administrative privileges.
3
Analyze routing configurations for remote worker bandwidth optimization.
Identify Split Tunneling as the setting that selectively directs internal corporate traffic through the tunnel.
Prevents non-work Internet browsing and video streaming from hairpinned consumption of perimeter internet bandwidth.
4
Identify centralized AAA framework protocols for remote connectivity.
Associate RADIUS with UDP-based identity validation across ports 1812 and 1813.
RADIUS integrates network access gateways with central authentication servers.

Anahtar Kavram

Remote Access Protocols, Encapsulation Modes, and AAA Integration
Bu soruyu puanla