EasyManuals Logo

Cisco 5510 - ASA SSL / IPsec VPN Edition User Manual

Cisco 5510 - ASA SSL / IPsec VPN Edition
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1590 background imageLoading...
Page #1590 background image
1-40
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring IPsec and ISAKMP
Supporting the Nokia VPN Client
Figure 1-5 Nokia 92xx Communicator Service Requirement
To support the Nokia VPN client, perform the following step on the ASA:
• Enable CRACK authentication using the crypto isakmp policy priority authentication command
with the crack keyword in global configuration mode. For example:
hostname(config)# crypto isakmp policy 2
hostname(config-isakmp-policy)# authentication crack
If you are using digital certificates for client authentication, perform the following additional steps:
Step 1 Configure the trustpoint and remove the requirement for a fully qualified domain name. The trustpoint
might be NSSM or some other CA. In this example, the trustpoint is named CompanyVPNCA:
hostname(config)# crypto ca trustpoint CompanyVPNCA
hostname(config-ca-trustpoint)# fqdn none
Step 2 To configure the identity of the ISAKMP peer, perform one of the following steps:
• Use the crypto isakmp identity command with the hostname keyword. For example:
hostname(config)# crypto isakmp identity hostname
• Use the crypto isakmp identity command with the auto keyword to configure the identity to be
automatically determined from the connection type. For example:
hostname(config)# crypto isakmp identity auto
Note If you use the crypto isakmp identity auto command, you must be sure that the DN attribute
order in the client certificate is CN, OU, O, C, St, L.
132777
Nokia SSM
Web server
Internet
Operator
mobile
network
Telecommuters
SSM server
and database
SSM
enrollment
gateway
SSM
management
station
RADIUS or
LDAP server
SAP
database
Corporate
E-mail
Corporate
Web services
Windows Clients/
Laptop Policy
Mobile Devices/
Mobile Devices
Policy
DMZ
Firewall/
VPN
gateway
Remote Access

Table of Contents

Other manuals for Cisco 5510 - ASA SSL / IPsec VPN Edition

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 5510 - ASA SSL / IPsec VPN Edition and is the answer not in the manual?

Cisco 5510 - ASA SSL / IPsec VPN Edition Specifications

General IconGeneral
BrandCisco
Model5510 - ASA SSL / IPsec VPN Edition
CategoryFirewall
LanguageEnglish

Related product manuals