Cisco PIX 525 Especificaciones Pagina 163

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 466
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 162
4-11
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 4 Using PIX Firewall in SOHO Networks
Using PIX Firewall as an Easy VPN Remote Device
The following command omits the DN, and as a result the PIX Firewall prompts for this information:
pixfirewall(config)# ca subject-name
Common name (cn) [pixfirewall.example.com] :pixfirewall.example.com
Department (ou) []: VSEC BU
Company(o) []:Cisco System
State (st) []:CA
Country (c) []:US
Email (e) []:[email protected]
Proceed with the above information [no]: yes
To display information about the current certification configuration, enter the following command:
pixfirewall(config)# show ca cert
…(PIX device cert)
Certificate
Status: Available
Certificate Serial Number: 45a490250000000000fa
Key Usage: General Purpose
Subject Name:
CN = myvpn01.example.com
OU = VSEC BU
O = Cisco System INC
UNSTRUCTURED NAME = myvpn01.example.com
Validity Date:
start date: 22:35:58 UTC Aug 16 2002
end date: 22:45:58 UTC Aug 16 2003
Verifying the DN of an Easy VPN Server
PIX Firewall Version 6.3, when used as an Easy VPN Remote device, lets you specify the DN of the
certificate used to establish a VPN tunnel. We recommend enabling this feature to prevent a possible
“man-in-the-middle” attack.
To verify the DN of the certificate received by your PIX Firewall, enter the following command:
ca verifycertdn x500 string
Note Every attribute must match exactly to verify the certificate received and to establish a VPN tunnel.
For example, a PIX Firewall used as an Easy VPN Remote Server might have the following certificate:
Certificate
Status: Available
Certificate Serial Number: 4ebdbd400000000000a2
Key Usage: General Purpose
Subject Name:
CN = myvpn01.myorg.com
OU = myou
O = myorg
ST = CA
C = US
UNSTRUCTURED NAME = myvpn01.myorg.com
Validity Date:
start date: 23:48:00 UTC Feb 18 2003
end date: 23:58:00 UTC Feb 18 2004
--------------------------------------------------------------------------------
Vista de pagina 162
1 2 ... 158 159 160 161 162 163 164 165 166 167 168 ... 465 466

Comentarios a estos manuales

Sin comentarios