cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3759
Views
0
Helpful
5
Replies

AnyConnect Client Certificate Firepower FTD

leighharrison
Level 7
Level 7

Hello folks,

 

When configuring Client-Certificate for AnyConnect VPN on Firepower, what does the FTD use to evaluate the Client Certificate?

 

I have the Root CA and Sub CA certs in the FMC under Trusted CA's, but I'm still getting authentication failure on Cert Only Authentication.  On the end user device it is saying no valid certificates available for authentication.

 

Best, Leigh

1 Accepted Solution

Accepted Solutions

I believe AnyConnect will look in the personal certificates folder of the respective store (User or Local Computer) that you've specified in the profile.

Local Computer certificate storeLocal Computer certificate store

View solution in original post

5 Replies 5

kapydan88
Level 4
Level 4

Hello.

 

Can you describe more exactly - how you generated caertificates and uploaded it inti FMC.

Hi,

 

I've got the certificate of the Root CA and the Sub CA and imported them into the FTD via FMC as PKCS12 in Devices > Certificates and their status is good.

 

Best, Leigh

Marvin Rhoads
Hall of Fame
Hall of Fame

In the VPN profile you should have specified for the client to use User, Machine or either certificate for authentication. The AnyConnect profile will then look in the local certificate store(s) for a certificate to present to the FTD headend.

Hi Marvin,

 

I've got that all set up with the certificate in the machine store and the profile set to request the machine cert, but it still comes back with "No valid certificates available for authentication".  Is there a specific certificate store anyconnect looks at?

 

Best, Leigh

I believe AnyConnect will look in the personal certificates folder of the respective store (User or Local Computer) that you've specified in the profile.

Local Computer certificate storeLocal Computer certificate store