EasyManuals Logo
Home>Cisco>Network Router>ISR 4000 series

Cisco ISR 4000 series User Manual

Cisco ISR 4000 series
66 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #41 background imageLoading...
Page #41 background image
Cisco ISR 4000 Family Routers Administrator Guidance
Page 41 of 66
Step2
(ca-certificate-map)# field-name match-
criteria match-value
In ca-certificate-map mode, you specify one or more
certificate fields together with their matching criteria and the
value to match.
field-nameSpecifies one of the following case-
insensitive name strings or a date:
subject-name
issuer-name
unstructured-subject-name
alt-subject-name
name
valid-start
expires-on
Note Date field format is dd mm yyyy hh:mm:ss or mm dd
yyyy hh:mm:ss.
match-criteriaSpecifies one of the following
logical operators:
eqEqual (valid for name and date fields)
neNot equal (valid for name and date fields)
coContains (valid only for name fields)
ncDoes not contain (valid only for name fields)
lt Less than (valid only for date fields)
ge Greater than or equal (valid only for date
fields)
match-valueSpecifies the name or date to test with
the logical operator assigned by match-criteria.
Step3
(ca-certificate-map)# exit
Exits ca-certificate-map mode.
Step4
For IKEv1:
crypto isakmp profile ikev1-profile1
match certificate label
For IKEv2:
crypto ikev2 profile ikev2-profile1
match certificate label
Associates the certificate-based ACL defined with the crypto
pki certificate map command to the profile.
For example: To create a certificate map for IKEv1 to match four subject-name values of the peer
enter:
# conf t
(config)# crypto pki certificate map cert-map-match-all 99
(ca-certificate-map)# subject-name co cn=CC_PEER
(ca-certificate-map)# subject-name co o=ACME
(ca-certificate-map)# subject-name co ou=North America

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ISR 4000 series and is the answer not in the manual?

Cisco ISR 4000 series Specifications

General IconGeneral
BrandCisco
ModelISR 4000 series
CategoryNetwork Router
LanguageEnglish

Related product manuals