EasyManuals Logo

Cisco ASA Series User Manual

Cisco ASA Series
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1590 background imageLoading...
Page #1590 background image
1-40
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring IPsec and ISAKMP
Supporting the Nokia VPN Client
Figure 1-5 Nokia 92xx Communicator Service Requirement
To support the Nokia VPN client, perform the following step on the ASA:
• Enable CRACK authentication using the crypto isakmp policy priority authentication command
with the crack keyword in global configuration mode. For example:
hostname(config)# crypto isakmp policy 2
hostname(config-isakmp-policy)# authentication crack
If you are using digital certificates for client authentication, perform the following additional steps:
Step 1 Configure the trustpoint and remove the requirement for a fully qualified domain name. The trustpoint
might be NSSM or some other CA. In this example, the trustpoint is named CompanyVPNCA:
hostname(config)# crypto ca trustpoint CompanyVPNCA
hostname(config-ca-trustpoint)# fqdn none
Step 2 To configure the identity of the ISAKMP peer, perform one of the following steps:
• Use the crypto isakmp identity command with the hostname keyword. For example:
hostname(config)# crypto isakmp identity hostname
• Use the crypto isakmp identity command with the auto keyword to configure the identity to be
automatically determined from the connection type. For example:
hostname(config)# crypto isakmp identity auto
Note If you use the crypto isakmp identity auto command, you must be sure that the DN attribute
order in the client certificate is CN, OU, O, C, St, L.
132777
Nokia SSM
Web server
Internet
Operator
mobile
network
Telecommuters
SSM server
and database
SSM
enrollment
gateway
SSM
management
station
RADIUS or
LDAP server
SAP
database
Corporate
E-mail
Corporate
Web services
Windows Clients/
Laptop Policy
Mobile Devices/
Mobile Devices
Policy
DMZ
Firewall/
VPN
gateway
Remote Access

Table of Contents

Other manuals for Cisco ASA Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA Series and is the answer not in the manual?

Cisco ASA Series Specifications

General IconGeneral
ModelASA 5505
InterfacesVaries by model (Fast Ethernet, Gigabit Ethernet, 10 Gigabit Ethernet, etc.)
High AvailabilityActive/Standby or Active/Active (varies by model)
Power SupplyVaries by model
Form FactorVaries by model
Operating SystemCisco ASA Software
IPsec VPNSupported
SSL VPNSupported
IPS ThroughputVaries by model

Related product manuals