cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
117
Views
8
Helpful
3
Replies
amardram123
Beginner

Urgent: ID & CA Cert installation in ASA for site-to-site vpn using PKI

Hi All,

I am running ASA 9.3 version and i need some supporting doc to install CA & identity cert in ASA either using ASDM or CLI for configuration.

Can anyone share good doc for this.

I have existing site-to-site VPN working using IKEV1 and preshared key, now customer wants to use secure authentication using certificate and IKEV2. Is anyone having good doc to refer the configuration for installing the cert and IKEV2 config.

I already have the cert.

your quick response will be appriciated.

Thanks

AMar.

3 REPLIES 3
Dinesh Moudgil
Cisco Employee

Here are few documents for your reference:-

Renew and Install the SSL Certificate with ASDM
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/107956-renew-ssl.html

Site-to-Site IKEv2 Tunnel between ASA and Router 
http://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/117337-config-asa-router-00.html

Regards,
Dinesh Moudgil

P.S. Please rate helpful posts.

Cisco Network Security Channel - https://www.youtube.com/c/CiscoNetSec/

Hi Dinesh,

thanks for your reply..

I was referring this doc earlier but this seems cert installation on 8.x . I am currently using 9.3 and  RSA authentication for site-to-site but below doc is for SSL. Do we have same config steps for IPsec site-to-site VPN running on 9.3 ?

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/107956-renew-ssl.html

Thanks

Amar

Hi Amar,

Here is a good link for creating a S2S tunnel using digital certs on ASA:

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/110221-asavpnclient-ca.html

There should not be no major change in the syntax. Instead of isakmp you would use ikev1 on 9.3 code.

Hope it helps.

Regards,

Aditya

Please rate helpful posts.

Content for Community-Ad