cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

632
Views
0
Helpful
2
Replies
CSCO12052693
Beginner

MSFT CA vs. ASA built-in CA

I'm trying to setup VPN users to authenticate with digital certificates as part of 2 factor authenication. With a 5510 (upgrading to 5515) with access to Microsoft 2008r and 2012, Which would be a better fit the Microsoft service or the built-in CA service on the ASA? (needed for less than 25 VPN users but would like setup for growth.)

Thanks,

Jeremy

1 ACCEPTED SOLUTION

Accepted Solutions
fashour
Beginner

You would get more benefit out of MS-CA. backups, scale, management, flexibility to use for other purposes if needed (wireless/dot1x for example) are some of the advantages. The Local CA works however and is considered more cost effective.

FaDi

View solution in original post

2 REPLIES 2
fashour
Beginner

You would get more benefit out of MS-CA. backups, scale, management, flexibility to use for other purposes if needed (wireless/dot1x for example) are some of the advantages. The Local CA works however and is considered more cost effective.

FaDi

View solution in original post

Thanks for the reply. Think I'll try out MS-CA.

Content for Community-Ad