cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
525
Views
0
Helpful
3
Replies

Preshared Certificates

jstabl
Level 1
Level 1

We are in the process of implimenting SSL VPN using the AnyConnect client. I am curious if it is possible to have a Pre-Shared Certificate that is self signed created and then I would manually install the cert. This would ensure that I control who accesses the network using VPN.

1 Accepted Solution

Accepted Solutions

JORGE RODRIGUEZ
Level 10
Level 10

What platform ASA? if so you can use Local CA configured in ASA and have user enrollment and installed in their PC all managed through the ASA applience.

Personally I have not used this method but from what I read very practical and all privided by asa .. I recommend to read couple of times The Local CA section of this link to get thorough understanding of its usage and implementation for SSL webVPN or client based vpn.

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/cert_cfg.html#wp1067484

HTH

Jorge

Jorge Rodriguez

View solution in original post

3 Replies 3

JORGE RODRIGUEZ
Level 10
Level 10

What platform ASA? if so you can use Local CA configured in ASA and have user enrollment and installed in their PC all managed through the ASA applience.

Personally I have not used this method but from what I read very practical and all privided by asa .. I recommend to read couple of times The Local CA section of this link to get thorough understanding of its usage and implementation for SSL webVPN or client based vpn.

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/cert_cfg.html#wp1067484

HTH

Jorge

Jorge Rodriguez

Jorge

That is exactly what method I researched and implemented a few days ago. It works really well and allows me to choose who I give certificates to and how long those certs are active. Users get an email with a one time password they use that password to retrieve the cert and then import in to Firefox or IE

Jake, thanks for the update and ratings, we are contemplating this inplementation as well, and Im glad to hear it works great.

Rgds

Jorge

Jorge Rodriguez
Review Cisco Networking for a $25 gift card