Duo and RTC for FTD Remote Access VPN
Which two features can be used with Cisco Secure Firewall Threat Defense remote access VPN? (Choose two.)
Community Votes
67% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests supported features for FTD remote access VPN, specifically Duo 2FA with LDAPS and RTC with RADIUS CoA, with the common trap being port sharing on 443.
Cisco Secure Firewall Threat Defense remote access VPN supports Duo two-factor authentication via LDAPS and Rapid Threat Containment (RTC) via RADIUS dynamic authorization. This page establishes why options A and E are the correct features and why port sharing is invalid.
Choosing C because SSL VPN typically uses port 443, but FTD requires exclusive use of this port and does not support port sharing for RA VPN.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Cisco Secure Firewall Threat Defense (FTD) remote access VPN supports Duo two-factor authentication using LDAPS, allowing integration with Duo's cloud service for secondary authentication. Additionally, FTD RA VPN supports Rapid Threat Containment (RTC) using RADIUS dynamic authorization (Change of Authorization), enabling the firewall to dynamically restrict or terminate user sessions based on threat postures. These two features are explicitly documented as supported for FTD remote access VPN configurations.Why the Other Options Are Wrong
Option B is incorrect because FTD remote access VPN does not support high availability clustering on the 4100 Series. Option C is a major trap; FTD explicitly prohibits port sharing on SSL port 443 with other features, requiring the port to be exclusively dedicated to the VPN. Option D is incorrect as license utilization for zero-touch network deployment is not a feature of remote access VPN.Community Comment Notes
Community members strongly agree that A and E are correct. As tinyJoe noted, "C is clearly wrong from the following documentation" which states "These ports must not be used on the threat defense device before configuring remote access VPN policy". artilling also confirmed "Rapid Threat Containment support using RADIUS CoA or RADIUS dynamic authorization" for option E, while acknowledging Duo LDAPS support despite its end-of-life status for direct cloud connections.Official Reference
Exam Strategy
For FTD remote access VPN questions, remember that SSL port 443 cannot be shared with other features and must be dedicated. Also, recall that RTC relies specifically on RADIUS dynamic authorization (CoA) to function with VPN sessions.