10-16-2008 06:04 AM - edited 03-11-2019 06:58 AM
We are in the process of implimenting SSL VPN using the AnyConnect client. I am curious if it is possible to have a Pre-Shared Certificate that is self signed created and then I would manually install the cert. This would ensure that I control who accesses the network using VPN.
Solved! Go to Solution.
10-22-2008 05:54 PM
What platform ASA? if so you can use Local CA configured in ASA and have user enrollment and installed in their PC all managed through the ASA applience.
Personally I have not used this method but from what I read very practical and all privided by asa .. I recommend to read couple of times The Local CA section of this link to get thorough understanding of its usage and implementation for SSL webVPN or client based vpn.
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/cert_cfg.html#wp1067484
HTH
Jorge
10-22-2008 05:54 PM
What platform ASA? if so you can use Local CA configured in ASA and have user enrollment and installed in their PC all managed through the ASA applience.
Personally I have not used this method but from what I read very practical and all privided by asa .. I recommend to read couple of times The Local CA section of this link to get thorough understanding of its usage and implementation for SSL webVPN or client based vpn.
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/cert_cfg.html#wp1067484
HTH
Jorge
10-23-2008 06:46 AM
Jorge
That is exactly what method I researched and implemented a few days ago. It works really well and allows me to choose who I give certificates to and how long those certs are active. Users get an email with a one time password they use that password to retrieve the cert and then import in to Firefox or IE
10-23-2008 07:47 AM
Jake, thanks for the update and ratings, we are contemplating this inplementation as well, and Im glad to hear it works great.
Rgds
Jorge
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide