EasyManuals Logo

Cisco ASR 1004 User Manual

Cisco ASR 1004
72 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #43 background imageLoading...
Page #43 background image
Page 43 of 72
4.7 Product Updates
Verification of authenticity of updated software is done in the same manner as ensuring that the
TOE is running a valid image. See Section 2, steps 7 and 9 above for the method to download
and verify an image prior to running it on the TOE.
4.8 Configure Reference Identifier
This section describes configuration of the peer reference identifier which is achieved through a
certificate map.
Certificate maps provide the ability for a certificate to be matched with a given set of criteria.
You can specify which fields within a certificate should be checked and which values those
fields may or may not have. There are six logical tests for comparing the field with the value:
equal, not equal, contains, does not contain, less than, and greater than or equal. ISAKMP and
ikev2 profiles can bind themselves to certificate maps, and the TOE will determine if they are
valid during IKE authentication.
Step1
(config)# crypto pki certificate map
label sequence-number
Starts certificate-map mode
Step2
(ca-certificate-map)# field-name match-
criteria match-value
In ca-certificate-map mode, you specify one or more
certificate fields together with their matching criteria and the
value to match.
field-nameSpecifies one of the following case-
insensitive name strings or a date:
subject-name
issuer-name
unstructured-subject-name
alt-subject-name
name
valid-start
expires-on
Note Date field format is dd mm yyyy hh:mm:ss or mm dd
yyyy hh:mm:ss.
match-criteriaSpecifies one of the following
logical operators:
eqEqual (valid for name and date fields)
neNot equal (valid for name and date fields)
coContains (valid only for name fields)
ncDoes not contain (valid only for name fields)
lt Less than (valid only for date fields)
ge Greater than or equal (valid only for date
fields)

Table of Contents

Other manuals for Cisco ASR 1004

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASR 1004 and is the answer not in the manual?

Cisco ASR 1004 Specifications

General IconGeneral
Product TypeRouter
Form FactorRack-mountable
Rack Height2U
Forwarding CapacityUp to 20 Gbps
Total Number of PortsVaries by configuration
Number of Total Expansion Slots4
Product SeriesASR 1000
ModelASR 1004
Forwarding PerformanceUp to 20 Gbps
Operating SystemCisco IOS XE
Power SupplyDual
Route ProcessorASR 1000 Series Route Processor
Network Interface ModulesSFP, SFP+, Gigabit Ethernet, 10 Gigabit Ethernet
Interfaces/PortsVaries by configuration
Expansion Slot TypeSPA
Throughput20 Gbps
RedundancyPower supply, Route Processor
InterfacesGigabit Ethernet, 10 Gigabit Ethernet, SFP, SFP+
StorageUp to 64 GB Flash

Related product manuals