cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
285
Views
0
Helpful
2
Replies

Cisco IPSec questions

kiksen1
Level 1
Level 1

Dear All,

I have some questions about authentication. When I

read the vpn3000 concentrator documentation, e.g.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_guide_chapter09186a008015c1ab.html#1105263

the paper talks about digital certificates.

Are the certificates used to do authentication with digital signatures or authentication with public key encryption or do I have the choice what I want to do?

If I want to do mainmode with digital certificates, does the initiator need a fix IP or is a dynamic IP possible?

Thank you!

Christian

2 Replies 2

gmiiller
Level 1
Level 1

Devices such as routers and VPN concentrators can use certificates for authentication purposes. By default, the logic applied when they evaluate a certificate presented for authentication is:

Is the certificate valid (date/time/crl)

Is the certificate from the same root CA

Although later code versions have more features incorporated around certificates and attributes, it's very clunky with concepts like overlapping cryptographic domains or realms.

No, you don't need a fixed address when using certificates.

Cerficiates have no role in the IPSec encryption process

Thank you for your response.

I read the paper "Certificate Security Attribute-Based Access Control". If I understand the paper right, now I can implement differentiated vpn access for "departments" or groups of certificate owners, where one attribute (e.g. OU) tells me, that this group gets access or not?

That all depends on, how my pki hierarchy looks like.

Thank you!

Christian

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: