27-29
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 27 Configuring IPSec and ISAKMP
Supporting the Nokia VPN Client
hostname(config-isakmp-policy)#
authentication crack
If you are using digital certificates for client authentication, perform the following additional steps:
Step 1
Configure the trustpoint and remove the requirement for a fully qualified domain name. The trustpoint
might be NSSM or some other CA. In this example, the trustpoint is named CompanyVPNCA:
hostname(config)#
crypto ca trustpoint CompanyVPNCA
hostname(config-ca-trustpoint)#
fqdn none
Step 2
To configure the identity of the ISAKMP peer, perform one of the following steps:
a.
Use the
crypto isakmp identity
command with the
hostname
keyword. For example:
hostname(config)#
crypto isakmp identity hostname
–or–
b.
Use the
crypto isakmp identity
command with the
auto
keyword to configure the identity to be
automatically determined from the connection type. For example:
hostname(config)#
crypto isakmp identity auto
Note
If you use the
crypto isakmp identity
auto
command, you must be sure that the DN attribute
order in the client certificate is CN, OU, O, C, St, L.
To learn more about the Nokia services required to support the CRACK protocol on Nokia clients, and
to ensure they are installed and configured properly, contact your local Nokia representative.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......