EasyManuals Logo

Alcatel-Lucent OmniAccess 5740 Cli Configuration Guide

Alcatel-Lucent OmniAccess 5740
1225 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #852 background imageLoading...
Page #852 background image
IP Security - Virtual Private Network
Left running head:
Chapter name (automatic)
826
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
Alcatel-Lucent
T
O CONFIGURE A STRICT CRL POLICY
By default, the OmniAccess 5740 USG has a lenient CRL policy, i.e., even if the
CRL is not present (not imported) or expired, the peer's certificate will be
accepted. There is an option of making this CRL policy strict.
E
XAMPLE
ALU(config)# crypto crl-check strict
ALU(config)# no crypto crl-check strict
T
O IMPORT A PEER’S SELF-SIGNED CERTIFICATE
The peer’s self-signed certificate can be imported to override the CA check. This
can be done if the peer is not enrolled with any of the trusted CAs and if the peer
is trusted. Thus one does not have to rely on the certificate to be transmitted by
the peer as part of the IKE protocol.
E
XAMPLE
ALU(config)# crypto peer-certificate cert_Bouvier import ftp:
Command (in CM) Description
crypto crl-check strict This command makes the CRL policy
strict.
It ensures that if no CRL is present or if
the CRL is already expired, then no
negotiation takes place until a new CRL
is imported.
no crypto crl-check strict This command makes the CRL policy
lenient.
Command (in CM) Description
crypto peer-certificate <name>
import {<certificate-content>
|fpkey <file-path>|ftp:|tftp:
|http:|https:|scp:}
This command imports trusted peer
certificates in the OmniAccess 5740
USG.
You also have an option to directly enter
or paste the certificate after the
command. Enter up to 80 characters on
a line. Enter a blank line to exit.
Note: Currently, SCP option is not
supported.

Table of Contents

Other manuals for Alcatel-Lucent OmniAccess 5740

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Alcatel-Lucent OmniAccess 5740 and is the answer not in the manual?

Alcatel-Lucent OmniAccess 5740 Specifications

General IconGeneral
BrandAlcatel-Lucent
ModelOmniAccess 5740
CategoryGateway
LanguageEnglish

Related product manuals