06-24-2017 06:32 AM
Hi There!
I'm currently using my 2901 to enable VPN access through PPTP and would like to enable digital certificates for VPN access in order to enhance security. I couldn't find much info about this setup on the web. I've got two questions in my mind:
1 - I have a fairly simple setup and no CA on my network. Can I use the 2901 to create the certificate for my VPN clients?
2 - How can I configure my 2901 to work with this setup?
Thanks!
Solved! Go to Solution.
06-26-2017 12:19 AM
PPTP is effectively deprecated. You should expect poor or buggy support.
This is an example I wrote of how to deploy Cisco AnyConnect on an IOS router using IKEv2 and certificates.
http://www.ifm.net.nz/cookbooks/Cisco-IOS-router-IKEv2-AnyConnect-Suite-B-Crypto.html
06-26-2017 12:19 AM
PPTP is effectively deprecated. You should expect poor or buggy support.
This is an example I wrote of how to deploy Cisco AnyConnect on an IOS router using IKEv2 and certificates.
http://www.ifm.net.nz/cookbooks/Cisco-IOS-router-IKEv2-AnyConnect-Suite-B-Crypto.html
06-26-2017 02:38 PM
Philip,
Fantastic, thank you for the direction. My clients will be using iphones to log on VPN. Should I follow the same recipe to import the certificates (just drop .pem files of the iPhone)?
06-26-2017 03:07 PM
Use the Cisco AnyConnect VPN client on iPhone to connect.
I believe you can just email the certificate to the user and then have the user double click on it to install the certificate.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide