cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
462
Views
0
Helpful
1
Replies

ASA Certification checking

I have assigned a new SSL certificate from an external provider and wanted to get client certificate checking working, previously the ASA was using an internal CA to provide the Identity certificate for the trust points but since adding the new SSL cert vpn will work with just AAA but no longer with AAA Certificate. From my understanding the as long as the internal CA is imported into the ASA  should be able to authenticate the user certificates provided to the users by the internal CA but this doesnt seem to be the case anyone able to shed some light on this situation?

Regards

1 Reply 1

jumukhi
Level 1
Level 1

Hi,

Can you please provide me the output of :

show crypto ca cert

show run all ssl

While initiatig a vpn connection please take following debugs:

debug crypto ca 255

debug crypto ca messages 255

debug crypto ca transactions 255

Thanks!