Cisco PIX 525 Spécifications Page 223

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 222
6-11
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 6 Configuring IPSec and Certification Authorities
Using Certification Authorities
Step 6 Configure the parameters of communication between the PIX Firewall and the CA:
ca configure ca_nickname ca | ra retry_period retry_count [crloptional]
For example:
ca configure myca.example.com ca 1 20 crloptional
If the PIX Firewall does not receive a certificate from the CA within 1 minute (the default) of sending a
certificate request, it will resend the certificate request. The PIX
Firewall will continue sending a
certificate request every 1 minute until a certificate is received or until 20 requests have been sent. With
the keyword crloptional included within the command statement, other peer’s certificates can still be
accepted by your PIX
Firewall even if the CRL is not accessible to your PIX Firewall.
Step 7 Authenticate the CA by obtaining its public key and its certificate:
ca authenticate ca_nickname [fingerprint]
For example:
ca authenticate myca.example.com 0123 4567 89AB CDEF 0123
The fingerprint (0123 4567 89AB CDEF 0123 in the example) is optional and is used to authenticate the
CAs public key within its certificate. The PIX
Firewall will discard the CA certificate if the fingerprint
that you included in the command statement is not equal to the fingerprint within the CAs certificate.
You also have the option to manually authenticate the public key by simply comparing the two
fingerprints after you receive the CAs certificate rather than entering it within the command statement.
Note Depending on the CA you are using, you may need to ask your local CA administrator for this
fingerprint.
Step 8 Request signed certificates from your CA for all of your PIX Firewall’s RSA key pairs. Before entering
this command, contact your CA administrator because they must authenticate your PIX
Firewall
manually before granting its certificate(s).
ca enroll ca_nickname challenge_password [serial] [ipaddress]
For example:
ca enroll myca.example.com mypassword1234567 serial ipaddress
The keyword mypassword1234567 in the example is a password, which is not saved with the
configuration. The options “serial” and “ipaddress” are included, which indicates the PIX
Firewall units
serial number and IP address will be included in the signed certificate.
Note The password is required in the event your certificate needs to be revoked, so it is crucial that
you remember this password. Note it and store it in a safe place.
The ca enroll command requests as many certificates as there are RSA key pairs. You will only need to
perform this command once, even if you have special usage RSA key pairs.
Note If your PIX Firewall reboots after you issued the ca enroll command but before you received the
certificate(s), reissue the command and notify the CA administrator.
Vue de la page 222
1 2 ... 218 219 220 221 222 223 224 225 226 227 228 ... 465 466

Commentaires sur ces manuels

Pas de commentaire