<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower VPN Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033793#M1109618</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Its in .crt format ??&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2024 18:13:39 GMT</pubDate>
    <dc:creator>benolyndav</dc:creator>
    <dc:date>2024-03-04T18:13:39Z</dc:date>
    <item>
      <title>Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022691#M1109363</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;WE are going be setting up 12 site to site vpns to a 3rd party provider and they have said they will send us their root cert and we just need to create intermediates for the 12 tunnels from the root cert, is this possible and if so how please.??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:02:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022691#M1109363</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-02-22T14:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022730#M1109364</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; are you sure they said create intermediates for the tunnels? You'd exchange root certificates and deploy to the FTD to mutual authenticate when establishing the VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022730#M1109364</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-02-22T14:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022732#M1109365</link>
      <description>&lt;P&gt;the VPN cert. or CA cert. ?&lt;BR /&gt;if VPN cert. then you can generate self signed cert. and send to them&amp;nbsp;&lt;BR /&gt;they will use this self signed for VPN auth&amp;nbsp;&lt;BR /&gt;&lt;A href="https://integratingit.wordpress.com/2018/11/10/ftd-vpn-with-certificates/" target="_blank"&gt;FTD VPN Certificate authentication – integrating IT (wordpress.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022732#M1109365</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-02-22T14:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022744#M1109366</link>
      <description>&lt;P&gt;check below guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/firepower_threat_defense_certificate_based_authentication.html#Cisco_Reference.dita_0baaa057-10eb-49cc-8d97-d3be75c7294f" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/firepower_threat_defense_certificate_based_authentication.html#Cisco_Reference.dita_0baaa057-10eb-49cc-8d97-d3be75c7294f&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2018/11/10/ftd-vpn-with-certificates/" target="_blank"&gt;https://integratingit.wordpress.com/2018/11/10/ftd-vpn-with-certificates/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022744#M1109366</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-02-22T14:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022758#M1109367</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Yes thats what I thought just use Root for the 12 tunnels, I never questioned it as it was in an email but its confusing.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022758#M1109367</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-02-22T14:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022823#M1109368</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;So if I want to Use 3rd party Root Cert where will this need adding my side, ???&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022823#M1109368</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-02-22T16:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022839#M1109369</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; you can just create a new trustpoint and import the CA certificate and then attach to the FTDs.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/objects-certs.html#task_blc_3nw_vy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/objects-certs.html#task_blc_3nw_vy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022839#M1109369</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-02-22T16:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022864#M1109370</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im still a bit confused if they send me a cert does this mean I can simply add this cert to our FTD or do I still have to do some form of enrollment .??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 17:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022864#M1109370</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-02-22T17:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022867#M1109371</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; yes use manual enrollment and import the peers CA certificate only.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 17:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5022867#M1109371</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-02-22T17:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033730#M1109613</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;would it still need adding to Trusted Root as well.???&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 16:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033730#M1109613</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-03-04T16:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033740#M1109614</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; I assume you are referring to Trusted CA under Objects &amp;gt; PKI? ..then no&lt;/P&gt;
&lt;P&gt;You enrol the certificates (under Devices &amp;gt; Certificates) to the FTD which creates the trustpoint on the FTD with the relevant certificates.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 16:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033740#M1109614</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-04T16:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033745#M1109615</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;So add cert enrollment give it a name, then select Manual and check CA only,&amp;nbsp; I try saving and it dosent allow me to move forward ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---Paste CA certificate in PEM format here ????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 17:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033745#M1109615</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-03-04T17:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033751#M1109616</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; you can import the CA certificate only (no identity certificate) since 6.7, I assume you are using 6.7 or newer?&lt;/P&gt;
&lt;P&gt;Can you provide a screenshot of what you are doing and the error in context please? How are you trying to import the certificate? You can just copy and paste the CA certificate contents into the field, assuming it's the correct format.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 17:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033751#M1109616</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-04T17:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033793#M1109618</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Its in .crt format ??&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 18:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033793#M1109618</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-03-04T18:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033800#M1109619</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; a PEM file can use .crt file extension. PEM files starts with -----BEGIN CERTIFICATE-----&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Open the CA certificate file into notepad, copy and paste this.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 18:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033800#M1109619</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-04T18:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033809#M1109621</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;so thats on there now under manual enrollment Manual (CA Only) thanks for that, whats the next step please ??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 18:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033809#M1109621</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-03-04T18:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033812#M1109622</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; ok, so is this enrolled under the FTD ( from FMC under Devices &amp;gt; Certificates)?&lt;/P&gt;
&lt;P&gt;If so this will have created the trustpoint on the FTD, from the FTD you can run "show crypto ca certificates" to confirm the trustpoint is created.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 18:47:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033812#M1109622</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-04T18:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033814#M1109623</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Ah Ah, I see it, do I have to create a cert map now?&lt;BR /&gt;thank you for your assistance so far&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 18:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5033814#M1109623</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-03-04T18:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5034171#M1109630</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And also I have used CA only for the enrollment,&amp;nbsp; In the documentation I see it states recieving an Identity Certificate ? its all rather confusing.?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 08:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5034171#M1109630</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-03-05T08:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5034173#M1109631</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes its in there I see it&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 08:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-vpn-question/m-p/5034173#M1109631</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2024-03-05T08:07:09Z</dc:date>
    </item>
  </channel>
</rss>

