ā05-02-2023 04:31 AM
Im trying to replace site VPN using PSK with certificates. We have an internal CA that I am using.
I found a similar post here but when I deploy, the FMS shows deploy error on the head end FTD saying the cert needs to be enrolled.
is there a document on how to config site to site using FTDs managed by FMC and using certs rather than PSK
ā05-02-2023 04:35 AM
@michael18 yes you need to enroll the certificates via the FMC to install on the FTD.
ā05-02-2023 07:07 AM
Hi Rob
thanks for the info. ive followed sections, Manual Enrolment and Manual Certificate Renewal
I can see the cert on the remote FTD now via cli but when I change the config to use the cert the FMC still shows the error when deploying the change
ā05-02-2023 07:13 AM
@michael18 so once you've defined the manual enrollment, you then had the CSR signed and imported the Identity Certificate to complete the process? Once you've done that the status will be as per the image below.
ā05-02-2023 07:28 AM
yes that all worked as expected
ā05-02-2023 07:39 AM
@michael18 looks ok. You selected the desired certificate under the VPN topology configuration? What is the output of "show crypto ca trustpoints" on the CLI of the FTD?
ā05-02-2023 07:51 AM
hi Rob. yes the correct cert has been applied to the vpn.
show output on remote ftd:
Thanks
ā05-02-2023 08:06 AM
Its the head end that seems to be the problem. Im testing this with a FTD connected to a broadband. The remote end is called test-vpn-lab. The head end is an active FTD2140 call DCFPR2140
ā05-02-2023 07:45 AM - edited ā05-02-2023 07:45 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: