cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
197
Views
0
Helpful
1
Replies

ASA 8.4 Bug?

Kemal Zuko
Level 1
Level 1

Hello,

I came up accross a weird situation when I was trying to apply a self signed cert to my SSL_VPN group as a test.

Here is what I came accross...

the command that I needed to use was "trust-point self" under my SSL_VPN group.

[code=..]
tunnel-group SSL_VPN ipsec-attributes
trust-point self
[/code]

As always its my habit to use the "?" to see my options. Once I got into the "tunnel-group SSL_VPN ipsec-attributes" and did the ? to see my options here is what I got...

[code..]
ASA1(config)# tunnel-group SSL_VPN ipsec-attributes
ASA1(config-tunnel-ipsec)# ?

tunnel-group configuration commands:
  authorization-required  Require users to authorize successfully in order to
                          connect (DEPRECATED)
  chain                   Enable sending certificate chain
  exit                    Exit from tunnel-group IPSec attribute configuration
                          mode
  help                    Help for tunnel group configuration commands
  ikev1                   Configure IKEv1
  isakmp                  Configure ISAKMP policy
  no                      Remove an attribute value pair
  peer-id-validate        Validate identity of the peer using the peer's
                          certificate
  radius-with-expiry      Enable negotiation of password update during RADIUS
                          authentication (DEPRECATED)
ASA1(config-tunnel-ipsec)#
[/code]

I do not see an option for

[code..]
trust-point self
[/code]

however when I tried to type it out and hit enter it took the command

[code..]
ASA1(config-tunnel-ipsec)# trust-point self
ASA1(config-tunnel-ipsec)#
[/code]

I am not too familiar with the 8.4 code, so I dont know if this is something to worry about or just let it go.

Thanks

1 Accepted Solution

Accepted Solutions

Julio Carvajal
VIP Alumni
VIP Alumni

My question would be... If you are configuring an SSL vpn what are you doing in the IPSec-atrributes

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

My question would be... If you are configuring an SSL vpn what are you doing in the IPSec-atrributes

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking products for a $25 gift card