07-14-2009 06:53 AM
I need help for this problem: I am using a Cisco 877 router to build IPSec/GRE tunnel over Internet to a Nokia firewall / Checkpoint VPN-1 NG box. We used to build the IPSec tunnel using pre-shared key at both ends, which works well. But this time the Nokia firewall end does not allow it, and always request "ISAKMP: auth RSA sig" instead (got it from debug crypto ISAKMP). There is a way to fix the problem by changing global settings for the firewall, but it is not allowed because other IPSec tunnels already terminated on that box.
So we have to use the router's self signed cert instead of pre-shared key for crypto. But I don't know what parameters to specify when configing "crypto key public-chain rsa". What information do I need to ask the Nokia firewall admin for? and what he has to do to manually generate/exchange the cert? I wonder if anyone has done this before, and please help if you do.
Thanks in advance
Tony
07-14-2009 09:14 AM
I have only done this between two routers and a Microsoft CA server, but in the simplest form all you need to do is enroll with the CA server and request a certificate which the CA server would then grant and both devices would have to do that. The below config is using a Microsoft CA server.
crypto key generate rsa general-keys modulus 1024
crypto pki trustpoint
enrollment mode ra
enrollment url http://
revocation-check crl
auto-enroll 70
crypto ca authenticate
crypto ca enroll
Maybe these two links can help
07-14-2009 09:54 AM
There is no internal CA server available and I am not sure if the firewall admin would agree to enroll to an external CA server. Is there any other way to fix it?
07-14-2009 09:59 AM
Its either the cisco or the checkpoint will act as a CA server or you have no choice but to change the authentication to pre shared keys. AFAIK it cant work without a CA server.
07-14-2009 08:36 PM
Is it possible for the router and the firewall exchange the RSA Sig directly?
I saw there were three options for auth:
Pre-shared
RSA-Encr (via CA server)
RSA-Sig
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide