cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
728
Views
3
Helpful
5
Replies

Configuring CRL FTD FDM

Using version v7.0.5 FDM (or any 7x) , is it possible to reference a certificate revocation List(CRL)?

For use with RA VPN (anyconnect / Secure Client). I know this is possible using FMC, however is this possible using FDM.

1 Accepted Solution

Accepted Solutions

I don't believe that is supported:

https://bst.cisco.com/quickview/bug/CSCvs19613

Even if you try to use the Flexconfig that wouldn't work as I remember the crypto command is a blacklisted command.

View solution in original post

5 Replies 5

I don't believe that is supported:

https://bst.cisco.com/quickview/bug/CSCvs19613

Even if you try to use the Flexconfig that wouldn't work as I remember the crypto command is a blacklisted command.

Using a 2100 series firepower with only GUI FDM for Remote Access VPN with anyconnect/secure client authenticated using Client Certificates only.

If we needed to revoke a client certificate (lost laptop etc). Visibility of the CRL would enable the Firepower to know that this client certificate had been revoked. If there is no mechanism for CRL that would remove client certificate only as an option. 

The next best option would be AAA (SAML, LDAP, RADIUS etc) & client certificate

 

If you should enable SAML on the FDM, please be aware that the FDM will error out when you try to push the changes if the SAML certificate has the "ca-check" enabled. Unlike the FMC, the FDM does not have any option to turn that feature off, and the Flexconfig won't allow you to do it due to the crypto command being blacklisted. So in that case you would need to use a third party tool such as OpenSSL or XCA to generate a new cert and its private key, disable the ca-check, import the cert and the private key into Azure, and finally import the cert into FDM.

Thanks Aref, I have already come across that issue. XCA worked a treat.
 
Regards,
Jonathan
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card