<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple SSL certificate on ASA or Router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154299#M359682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK Thanks for replys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guys please forget the ASA, now i'm asking about Router.&lt;/P&gt;&lt;P&gt;I want to have my certificate on my router no for vpn purpose.&lt;/P&gt;&lt;P&gt;I want to publish my exchange and lync server on my router and they have different ip addresses and different FQDN.&lt;/P&gt;&lt;P&gt;I need to use two ip address on same interface, IP secondary.&lt;/P&gt;&lt;P&gt;And i'm going to assign private ip address on both servers and Nat them on Cisco Router.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So users on internet use these links &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://RouterIPaddress1"&gt;https://RouterIPaddress1&lt;/A&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://RouterIPaddress2"&gt;https://RouterIPaddress2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What now?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Mar 2013 16:54:28 GMT</pubDate>
    <dc:creator>mrmozaffari</dc:creator>
    <dc:date>2013-03-22T16:54:28Z</dc:date>
    <item>
      <title>Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154294#M359677</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible to install multiple SSL certificate on Router or ASA?&lt;/P&gt;&lt;P&gt;I have two subdomains exchange.xyz.com and dialin.xyz.com and there is have one certificate for both but for Lync.abc.com i have another SSL certificate, as an example &lt;SPAN style="font-size: 10pt;"&gt;exchange.xyz.com and dialin.xyz.com ip address is a.b.c.55&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;and Lync.abc.com is abc.60&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Advise.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154294#M359677</guid>
      <dc:creator>mrmozaffari</dc:creator>
      <dc:date>2019-03-12T01:17:56Z</dc:date>
    </item>
    <item>
      <title>Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154295#M359678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have more than one SSL certificate on your ASA but at the time of applying it to an interface you can just use one &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 00:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154295#M359678</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-22T00:39:12Z</dc:date>
    </item>
    <item>
      <title>Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154296#M359679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about Router?&lt;/P&gt;&lt;P&gt;And please tell me what do you mean at the time?&lt;/P&gt;&lt;P&gt;If it means you can only assign one certificate to your interface why it is possible to have more than one certificate in your firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 00:50:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154296#M359679</guid>
      <dc:creator>mrmozaffari</dc:creator>
      <dc:date>2013-03-22T00:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154297#M359680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;And please tell me what do you mean at the time?&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;If it means you can only assign one certificate to your interface why it is possible to have more than one certificate in your firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It means that you can have only one certicate on each interface, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same thing on the routers, one Certiface/trustpoint&amp;nbsp; per interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 00:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154297#M359680</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-22T00:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154298#M359681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As mentioned by Julio, you can only have one ssl trustpoint per interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;However, &lt;/STRONG&gt;you can have multiple SSL certificates on each device. Maybe for certificate authentication purposes, you do not apply these certificates on interface though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could have more than one domain on the ASA, just set up a VPN load-balancing cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-5964"&gt;&lt;STRONG&gt;ASA VPN Load Balancing/Clustering with Digital Certificates Deployment Guide&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have one certificate applied to the outside interface and one applied to the VPN cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Portu.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 02:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154298#M359681</guid>
      <dc:creator>Javier Portuguez</dc:creator>
      <dc:date>2013-03-22T02:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154299#M359682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK Thanks for replys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guys please forget the ASA, now i'm asking about Router.&lt;/P&gt;&lt;P&gt;I want to have my certificate on my router no for vpn purpose.&lt;/P&gt;&lt;P&gt;I want to publish my exchange and lync server on my router and they have different ip addresses and different FQDN.&lt;/P&gt;&lt;P&gt;I need to use two ip address on same interface, IP secondary.&lt;/P&gt;&lt;P&gt;And i'm going to assign private ip address on both servers and Nat them on Cisco Router.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So users on internet use these links &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://RouterIPaddress1"&gt;https://RouterIPaddress1&lt;/A&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://RouterIPaddress2"&gt;https://RouterIPaddress2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What now?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 16:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/2154299#M359682</guid>
      <dc:creator>mrmozaffari</dc:creator>
      <dc:date>2013-03-22T16:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4489086#M1084499</link>
      <description>&lt;P&gt;Julio, is it possible to have the same SSL certificate for two different interfaces (In my case on Cisco ASA 9.14)? I don't want to affect connected VPN users, so I'm afraid to change the configuration.&lt;BR /&gt;&lt;BR /&gt;This is the relevant part of the configuration.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ssl trust-point &lt;EM&gt;Certificate_Trustpoint_Name&lt;/EM&gt;&amp;nbsp;&lt;STRONG&gt;outside&lt;/STRONG&gt;&lt;BR /&gt;webvpn&lt;BR /&gt;enable &lt;STRONG&gt;outside&lt;/STRONG&gt;&lt;BR /&gt;enable &lt;STRONG&gt;visitors&lt;/STRONG&gt;&lt;BR /&gt;http-headers&lt;BR /&gt;hsts-server&lt;BR /&gt;enable&lt;BR /&gt;max-age 31536000&lt;BR /&gt;include-sub-domains&lt;BR /&gt;no preload&lt;BR /&gt;hsts-client&lt;BR /&gt;enable&lt;BR /&gt;x-content-type-options&lt;BR /&gt;x-xss-protection&lt;BR /&gt;content-security-policy&lt;BR /&gt;anyconnect image disk0:/anyconnect-win-4.5.03040-webdeploy-k9.pkg 1&lt;BR /&gt;anyconnect image disk0:/anyconnect-macos-4.5.03040-webdeploy-k9.pkg 2&lt;BR /&gt;anyconnect image disk0:/anyconnect-linux64-4.5.03040-webdeploy-k9.pkg 3&lt;BR /&gt;anyconnect enable&lt;BR /&gt;cache&lt;BR /&gt;disable&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;When I'm connecting to "outside" everything is going right. But when I'm trying to connect to "visitors" so I'm getting a ASA temporary self signed certificate.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for your reply and I apologize for my English.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 10:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4489086#M1084499</guid>
      <dc:creator>MarecekSK</dc:creator>
      <dc:date>2021-10-20T10:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4489766#M1084533</link>
      <description>&lt;P&gt;I was trying to change config at night.&lt;BR /&gt;It is possible to use same SSL trustpoint on different interfaces.&amp;nbsp;&lt;BR /&gt;I was afraid that the originally entered command (for interface outside) would be overwritten.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-HQ# sh run | i ssl trust&lt;BR /&gt;ssl trust-point &lt;EM&gt;CERTIFICATE_NAME_24032021&lt;/EM&gt; outside&lt;BR /&gt;ssl trust-point &lt;EM&gt;CERTIFICATE_NAME_24032021&lt;/EM&gt; visitors&lt;BR /&gt;ASA-HQ# sh crypto ssl&lt;BR /&gt;Accept connections using SSLv3 or greater and negotiate to TLSv1.2 or greater&lt;BR /&gt;Start connections using TLSv1.2 and negotiate to TLSv1.2 or greater&lt;BR /&gt;SSL DH Group: group24 (2048-bit modulus, 256-bit prime order subgroup, FIPS) (DEPRECATED)&lt;BR /&gt;SSL ECDH Group: group19 (256-bit EC)&lt;/P&gt;&lt;P&gt;SSL trust-points:&lt;BR /&gt;Self-signed (RSA 2048 bits RSA-SHA256) certificate available&lt;BR /&gt;Self-signed (EC 256 bits ecdsa-with-SHA256) certificate available&lt;BR /&gt;Interface outside: &lt;EM&gt;CERTIFICATE_NAME_24032021&lt;/EM&gt; (RSA 4096 bits RSA-SHA256)&lt;BR /&gt;Interface visitors: &lt;EM&gt;CERTIFICATE_NAME_24032021&lt;/EM&gt; (RSA 4096 bits RSA-SHA256)&lt;BR /&gt;Certificate authentication is not enabled&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 09:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4489766#M1084533</guid>
      <dc:creator>MarecekSK</dc:creator>
      <dc:date>2021-10-21T09:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4490252#M1084555</link>
      <description>&lt;P&gt;The discussion you are replying to is from 2013.&lt;/P&gt;
&lt;P&gt;Please start a new discussion and present your use case for a better understanding of what you want to do.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 03:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4490252#M1084555</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-10-22T03:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SSL certificate on ASA or Router</title>
      <link>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4490311#M1084560</link>
      <description>&lt;P&gt;It isn't needed. As I mentioned in the previous reply, I was trying to change the config at night(outside production hours) and my question was answered by this successful change.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 06:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-ssl-certificate-on-asa-or-router/m-p/4490311#M1084560</guid>
      <dc:creator>MarecekSK</dc:creator>
      <dc:date>2021-10-22T06:09:41Z</dc:date>
    </item>
  </channel>
</rss>

