An organization is planning to deploy a remote access VPN for employees. The solution must support strong encryption, mutual authentication, and work through firewalls without requiring additional ports. Which technology is most suitable?
SSL/TLS VPN tunnels over TCP 443, so it traverses existing firewall rules without opening extra ports, satisfying that constraint. It supports strong encryption and mutual authentication through client certificates, letting the organisation verify both user and server identities during the remote access session.
Why this answer
SSL/TLS VPNs (e.g., clientless or client-based SSL VPNs) use TLS over TCP port 443, which is almost universally allowed through firewalls, and they support strong encryption (AES) and mutual authentication via certificates or client certificates. Because they ride on standard HTTPS, no additional ports need to be opened, satisfying all stated requirements.
How to eliminate wrong answers
Option A is wrong because L2TP/IPsec uses UDP ports 500 and 4500 and IP protocol 50 (ESP), which often require firewall changes and can be blocked by NAT, failing the 'no additional ports' requirement. Option B is wrong because PPTP is obsolete and insecure, using weak MS-CHAPv2 authentication and RC4 encryption, and it uses TCP 1723 and GRE (protocol 47), which many firewalls block. Option C is wrong because IPsec tunnel mode also relies on ESP/IKE ports and protocols that frequently need explicit firewall rules and can struggle with NAT traversal, so it does not meet the 'work through firewalls without additional ports' criterion as cleanly as SSL/TLS VPN.