Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello,on a VPN 3005 Concentrator (Software Rev. 4.0.1) I try to download CRLs (Certificate Revocation Lists) to check if client certificates were revoked by the CA. The download works, but I get the following message:CAPI - RSA PKCS1 payload to be de...
Hello!I know about the features for using certificates with the Cisco VPN Client and VPN Concentrator/PIX. These features still don't satisfy our needs because to my opinion there is no real user authentication. Let me explain this:If a user "authent...
Hello,Because of large ACLs we need to activate NetFlow on all interfaces of a specific router. But to prevent double counting of flows which pass several routers we'd like to exclude an interface from NetFlow exporting. Is this possible?Thanks
Hello!Does anyone know how I can assign a software-client user to a specific group by his IP address? If it's not possible to configure this in group options - is there another way e.g. by filters?
Hello,we try to identify vpn client users by their certificates by checking the certificate's serial number on the vpn concentrator. That for I have set up a rule in the Group Matching Tab. When I use the "Organisation"-field (O="Organisation") every...
Thanks,but exactly that is my problem. If I don't activate ip route-cache flow on that interface the router's performance load raises up to a critical level. So when I need it on that interface - can I avoid exporting cache entries only from that spe...
Hi and thanks for your answer,I don't know if I explained my problem clearly enough. The task is to assign a user to a group by his origin IP-address, not by the address he got from the concentrator during the connection. For LAN-to-LAN sessions I ca...
I understood that a value can only be checked if it appears in the DN field. This didn't make it easier but I found a way to include an identifier (not certificate's serial number) in that field. If the identifier (SER) matches one in my rules even a...
By the way,I've tested several Client versions in the mean time. The Error occurs on all versions I've tested: 4.03A, 4.03C, 4.03D, 4.04, except 4.02B.
Thanks for your response.I couldn't find a bug description from Cisco yet. Don't they know or don't they care? Could you find any problem apart from the error message itself?