CISCO ASA VPN

Davidedi
Davidedi used Ask the Experts™
on
Hi

Can you setup a Cisco ASA remote access vpn client using IPSEC with a digital certificate? I have at the moment the standard Cisco ipsec vpn client using radius authentication with AD which works but I want to use if possible a digital certificate in addition to the ipsec vpn on the vpn client I see on the client you can import a certificate and use mutual authentication but I am not sure 1) if it is possible and 2) Cannot find any doco on Cisco that has a config example of a ipsec vpn client with a certificate authentication
 
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
yes it is possible you have to use authentication method as digital certificate rather than pre-shared key

Commented:
well ya its possible. In mutual authentication, only server certificate is reqd. In certificate authentication, even the client certificate is reqd.'
For client end, read this:
http://www.cisco.com/en/US/docs/security/vpn_client/cisco_vpn_client/vpn_client46/win/user/guide/vc6.html
For server end,
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080930f21.shtml

Author

Commented:
Hi Thanks for the info Do you know if the ASA can create and can you issue the certificate itself instead of using a Microsoft CA server ?

Commented:
nope.. asa cant be a ca server. but it can generate self-signed certificate for itself...

Author

Commented:
Ok what is a self signed certificate and can it substitute instead of a root ca or the Microsoft CA for the Cisco IPSec van client with certificate?
Commented:
In case if you are using certificates authentication on both side, its useless. It will work if u r using mutual authentication as only server certificate is reqd. Otherwise, u have to make a CA server. U can either make use of Microsoft CA server or use a router as CA server.

Author

Commented:
good

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial