
The ACS functions as an SSL server and has obtained a digital certificate from the CA. You
need to configure the Router as an SSL client to authenticate the ACS. This ensures privacy and
integrity of data exchanged between the Router and the ACS.
Figure 11-5
Networking diagram of the client SSL policy configuration
Internet
Router
ACS
Analog phone
Fax
IP phone
PC
LSW
CWMP
CA
Eth1/0/0
11.1.1.1/24
11.137.145.158/24
11.2.2.58/24
Configuration Roadmap
The configuration roadmap is as follows:
1.
Configure a PKI entity and a PKI domain.
2.
Configure a client SSL policy on the Router and enable SSL server authentication in the
policy.
3.
Apply the client SSL policy to the CWMP service so that the Router authenticates the ACS
to ensure data privacy and integrity.
4.
Enable the Router to automatically initiate connections to the ACS and set the CWMP
parameters. This enables the ACS to manage and control the Router using CWMP.
Data Preparation
To complete the configuration, you need the following data:
l
PKI domain name: cwmp0
l
Client SSL policy name: sslclient
l
IP address of the CA: 11.137.145.158/24
l
URL of the ACS: https://www.acs.com:80/acs
l
PKI parameters, as shown in the following table.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
11 SSL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
228