For what purpose is the Cisco ASA appliance web launch SSL VPN feature used?
A.
to enable split tunneling when using clientless SSL VPN access
B.
to enable users to login to a web portal to download and launch the AnyConnect client
C.
to enable smart tunnel access for applications that are not web-based
D.
to optimize the SSL VPN connections using DTLS
E.
to enable single-sign-on so the SSL VPN users need only log in once
Explanation:
http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect24/administration/g
uide/ac01intro.html
AnyConnect Standalone and WebLaunch Options
The user can use the AnyConnect Client in the following modes:
•Standalone mode—Lets the user establish a Cisco AnyConnect VPN client connection without the
need to use a web browser. If you have permanently installed the AnyConnect client on the user’s
PC, the user can run in standalone mode. In standalone mode, a user opens the AnyConnect client
just like any other application and enters the username and password credentials into the fields ofthe AnyConnect GUI. Depending on how you configure the system, the user might also be required
to select a group. When the connection is established, the security appliance checks the version of
the client on the user’s PC and, if necessary, downloads the latest version.
•WebLaunch mode—Lets the user enter the URL of the security appliance in the Address or Location
field of a browser using the https protocol. The user then enters the username and password
information on a Logon screen and selects the group and clicks submit. If you have specified a
banner, that information appears, and the user acknowledges the banner by clicking Continue.
The portal window appears. To start the AnyConnect client, the user clicks Start AnyConnect on the
main pane. A series of documentary windows appears. When the Connection Established dialog box
appears, the connection is working, and the user can proceed with online activities.
Whether connecting via standalone mode or WebLaunch mode, the AnyConnect client package must
be installed on the security appliance in order for the client to connect. This ensures that the
security appliance is the single point of enforcement as to which versions of the client can establish a
session, even if you deploy the client with an enterprise software deployment system. When you
load a client package on the security appliance, you enforce a policy that only versions as new as the
one loaded can connect. AnyConnect users must upgrade their clients by loading the latest version
of the client with the latest security features on the security appliance.